First published: Tue Nov 01 2022(Updated: )
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction
Credit: security@xen.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/xen | <=4.11.4+107-gef32c7afa2-1 | 4.14.6-1 4.14.5+94-ge49571868d-1 4.17.1+2-gb773c48e36-1 4.17.2+55-g0b56bed864-1 |
Xen Xen | ||
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42317 is a vulnerability in Xen that allows malicious guests to cause xenstored to allocate vast amounts of memory, leading to a Denial of Service (DoS) attack.
CVE-2022-42317 has a severity value of 6.5, which is considered medium.
This vulnerability can be exploited by malicious guests running on Xen to exhaust the memory resources of xenstored, resulting in a DoS attack.
The software versions affected by CVE-2022-42317 include Xen versions 4.11.4+107-gef32c7afa2-1 and earlier.
You can find more information about CVE-2022-42317 on the Xen Project website and the Debian Security Tracker.