PT-2022-7328 · Xenstore+1 · Xenstore+1

Julien Grall

·

Published

2022-11-01

·

Updated

2025-05-05

·

CVE-2022-42316

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xenstore (affected versions not specified)
Description The issue is related to the uncontrolled allocation of resources in Xenstore, which can lead to a Denial of Service (DoS) of xenstored. Malicious guests can cause xenstored to allocate large amounts of memory through various methods, including:
  • issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory
  • causing a large number of watch events to be generated via setting up multiple xenstore watches and then deleting many xenstore nodes below the watched path
  • creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible
  • accessing many nodes inside a transaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03584
CVE-2022-42316
DSA-5272-1
OPENSUSE-SU-2022_3947-1
OPENSUSE-SU-2022_4007-1
SUSE-SU-2022:3925-1
SUSE-SU-2022:3928-1
SUSE-SU-2022:3947-1
SUSE-SU-2022:3960-1
SUSE-SU-2022:3971-1
SUSE-SU-2022:4007-1
SUSE-SU-2022:4051-1
SUSE-SU-2022:4241-1
SUSE-SU-2022:4332-1

Affected Products

Suse
Xenstore