CVE-2022-42313
Summary
| CVE | CVE-2022-42313 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-01 13:15:00 UTC |
| Updated | 2023-11-07 03:53:00 UTC |
| Description | Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction |
NVD Known Affected Configurations (CPE 2.3)
Vendor Comments And Credit
Discovery Credit
LEGACY: Array
Legacy QID Mappings
- 181193 Debian Security Update for xen (DSA 5272-1)
- 184080 Debian Security Update for xen (CVE-2022-42313)
- 283293 Fedora Security Update for xen (FEDORA-2022-07438e12df)
- 283319 Fedora Security Update for xen (FEDORA-2022-99af00f60e)
- 283430 Fedora Security Update for xen (FEDORA-2022-9f51d13fa3)
- 390275 Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2023-0005)
- 502600 Alpine Linux Security Update for xen
- 502619 Alpine Linux Security Update for xen
- 503143 Alpine Linux Security Update for xen
- 503695 Alpine Linux Security Update for xen
- 504549 Alpine Linux Security Update for xen
- 505964 Alpine Linux Security Update for xen
- 752778 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3925-1)
- 752781 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3928-1)
- 752792 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3947-1)
- 752796 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3971-1)
- 752807 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4007-1)
- 752887 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4241-1)
- 752979 SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4332-1)