CVE-2022-42309: High severity XEN Xen vulnerability
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xento a version that resolves this vulnerability.Fixed in 4.14.6-1Fixed in 4.14.5+94-ge49571868d-1Fixed in 4.17.1+2-gb773c48e36-1Fixed in 4.17.2+55-g0b56bed864-1
Event History
Frequently Asked Questions
What is CVE-2022-42309?
CVE-2022-42309 is a vulnerability that allows a malicious guest to crash xenstored or cause memory corruption in xenstored, resulting in further damage.
How does CVE-2022-42309 affect Xen?
CVE-2022-42309 affects Xen in versions 4.11.4+107-gef32c7afa2-1, 4.14.6-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, 4.17.2+55-g0b56bed864-1 and can cause a crash of xenstored or memory corruption.
How can a malicious guest exploit CVE-2022-42309?
A malicious guest can exploit CVE-2022-42309 by causing xenstored to use a wrong pointer during node creation in an error path.
What is the severity of CVE-2022-42309?
CVE-2022-42309 has a severity rating of 8.8 (high).
How can I fix CVE-2022-42309?
To fix CVE-2022-42309, update Xen to a version that includes the appropriate fix, such as 4.14.6-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, or 4.17.2+55-g0b56bed864-1.