CVE-2022-42318: Medium severity XEN Xen vulnerability
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xento a version that resolves this vulnerability.Fixed in 4.14.6-1Fixed in 4.14.5+94-ge49571868d-1Fixed in 4.17.1+2-gb773c48e36-1Fixed in 4.17.2+55-g0b56bed864-1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-42318.
What is the severity of CVE-2022-42318?
The severity of CVE-2022-42318 is medium with a CVSS score of 6.5.
How does CVE-2022-42318 affect Xen Xen?
CVE-2022-42318 affects Xen Xen, allowing malicious guests to cause xenstored to allocate excessive memory, leading to a Denial of Service (DoS) attack.
How can I fix CVE-2022-42318 on Debian Debian Linux?
To fix CVE-2022-42318 on Debian Debian Linux, update the xen package to version 4.14.6-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, or 4.17.2+55-g0b56bed864-1.
Where can I find more information about CVE-2022-42318?
You can find more information about CVE-2022-42318 at the following references: [Xen Advisory](https://xenbits.xen.org/xsa/advisory-326.html), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2022-42318), [Xen Advisory Archive](http://xenbits.xen.org/xsa/advisory-326.html).