PT-2022-7326 · Xen+1 · Xenstore+1

Julien Grall

·

Published

2022-11-01

·

Updated

2022-12-06

·

CVE-2022-42311

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xenstore (affected versions not specified)
Description The issue is related to the Xenstore component of the Xen hypervisor, where malicious guests can cause xenstored to allocate large amounts of memory. This can result in a Denial of Service (DoS) of xenstored. There are multiple ways guests can cause large memory allocations, including issuing new requests without reading responses, causing a large number of watch events, creating many nodes with maximum size and path length, and accessing many nodes inside a transaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03582
CVE-2022-42311
DSA-5272-1
OPENSUSE-SU-2022_3947-1
OPENSUSE-SU-2022_4007-1
SUSE-SU-2022:3925-1
SUSE-SU-2022:3928-1
SUSE-SU-2022:3947-1
SUSE-SU-2022:3960-1
SUSE-SU-2022:3971-1
SUSE-SU-2022:4007-1
SUSE-SU-2022:4051-1
SUSE-SU-2022:4241-1
SUSE-SU-2022:4332-1

Affected Products

Suse
Xenstore