{"api_version":"1","generated_at":"2026-04-22T23:53:36+00:00","cve":"CVE-2022-42320","urls":{"html":"https://cve.report/CVE-2022-42320","api":"https://cve.report/api/cve/CVE-2022-42320.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-42320","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-42320"},"summary":{"title":"CVE-2022-42320","description":"Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time window when a new domain is created, where the access rights of a past domain with the same domid as the new one will be regarded to be still valid, leading to the new domain being able to get access to a node which was meant to be accessible by the removed domain. For this to happen another domain needs to write the node before the newly created domain is being introduced to Xenstore by dom0.","state":"PUBLIC","assigner":"security@xen.org","published_at":"2022-11-01 13:15:00","updated_at":"2024-02-04 08:15:00"},"problem_types":["CWE-459"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/","name":"FEDORA-2022-9f51d13fa3","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 37 Update: xen-4.16.2-4.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://security.gentoo.org/glsa/202402-07","name":"GLSA-202402-07","refsource":"","tags":[],"title":"Xen: Multiple Vulnerabilities (GLSA 202402-07) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://xenbits.xen.org/xsa/advisory-417.html","name":"http://xenbits.xen.org/xsa/advisory-417.html","refsource":"CONFIRM","tags":[],"title":"XSA-417 - Xen Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/","name":"FEDORA-2022-9f51d13fa3","refsource":"","tags":[],"title":"[SECURITY] Fedora 37 Update: xen-4.16.2-4.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2022/dsa-5272","name":"DSA-5272","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-5272-1 xen","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.openwall.com/lists/oss-security/2022/11/01/7","name":"[oss-security] 20221101 Xen Security Advisory 417 v2 (CVE-2022-42320) - Xenstore: Guests can get access to Xenstore nodes of deleted domains","refsource":"MLIST","tags":[],"title":"oss-security - Xen Security Advisory 417 v2 (CVE-2022-42320) - Xenstore: Guests\n can get access to Xenstore nodes of deleted domains","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/","name":"FEDORA-2022-07438e12df","refsource":"","tags":[],"title":"[SECURITY] Fedora 36 Update: xen-4.16.2-3.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://xenbits.xenproject.org/xsa/advisory-417.txt","name":"https://xenbits.xenproject.org/xsa/advisory-417.txt","refsource":"MISC","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/","name":"FEDORA-2022-07438e12df","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 36 Update: xen-4.16.2-3.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/","name":"FEDORA-2022-99af00f60e","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: xen-4.15.3-7.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/","name":"FEDORA-2022-99af00f60e","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: xen-4.15.3-7.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-42320","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42320","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Array","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"42320","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"42320","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"42320","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"42320","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"37","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"42320","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-42320","qid":"181193","title":"Debian Security Update for xen (DSA 5272-1)"},{"cve":"CVE-2022-42320","qid":"184900","title":"Debian Security Update for xen (CVE-2022-42320)"},{"cve":"CVE-2022-42320","qid":"283293","title":"Fedora Security Update for xen (FEDORA-2022-07438e12df)"},{"cve":"CVE-2022-42320","qid":"283319","title":"Fedora Security Update for xen (FEDORA-2022-99af00f60e)"},{"cve":"CVE-2022-42320","qid":"283430","title":"Fedora Security Update for xen (FEDORA-2022-9f51d13fa3)"},{"cve":"CVE-2022-42320","qid":"390275","title":"Oracle Managed Virtualization (VM) Server for x86 Security Update for xen (OVMSA-2023-0005)"},{"cve":"CVE-2022-42320","qid":"502600","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-42320","qid":"502619","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-42320","qid":"503143","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-42320","qid":"503695","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-42320","qid":"504549","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-42320","qid":"505964","title":"Alpine Linux Security Update for xen"},{"cve":"CVE-2022-42320","qid":"710858","title":"Gentoo Linux Xen Multiple Vulnerabilities (GLSA 202402-07)"},{"cve":"CVE-2022-42320","qid":"752778","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3925-1)"},{"cve":"CVE-2022-42320","qid":"752781","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3928-1)"},{"cve":"CVE-2022-42320","qid":"752792","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3947-1)"},{"cve":"CVE-2022-42320","qid":"752796","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:3971-1)"},{"cve":"CVE-2022-42320","qid":"752807","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4007-1)"},{"cve":"CVE-2022-42320","qid":"752887","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4241-1)"},{"cve":"CVE-2022-42320","qid":"752979","title":"SUSE Enterprise Linux Security Update for xen (SUSE-SU-2022:4332-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@xen.org","ID":"CVE-2022-42320","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"xen","version":{"version_data":[{"version_affected":"?","version_value":"consult Xen advisory XSA-417"}]}}]},"vendor_name":"Xen"}]}},"configuration":{"configuration_data":{"description":{"description_data":[{"lang":"eng","value":"All versions of Xen are in principle vulnerable.\n\nOnly systems running the C variant of Xenstore (xenstored or xenstore-\nstubdom) are vulnerable.\n\nSystems using the Ocaml variant of Xenstore (oxenstored) are not vulnerable.\n\nVulnerable systems are only those running software where one domain is\ngranted access to another's xenstore nodes, without complete cleanup\nof those nodes on domain destruction.  No such software is enabled in\ndefault configurations of upstream Xen.\n\nTherefore upstream Xen, without additional management software (in\nhost or guest(s)), is not vulnerable in the default (host and guest)\nconfiguration."}]}}},"credit":{"credit_data":{"description":{"description_data":[{"lang":"eng","value":"This issue was discovered by Jürgen Groß of SUSE."}]}}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time window when a new domain is created, where the access rights of a past domain with the same domid as the new one will be regarded to be still valid, leading to the new domain being able to get access to a node which was meant to be accessible by the removed domain. For this to happen another domain needs to write the node before the newly created domain is being introduced to Xenstore by dom0."}]},"impact":{"impact_data":{"description":{"description_data":[{"lang":"eng","value":"In some circumstances, it might be possible for a new guest domain to\naccess resources belonging to a previous domain.  The impact would\ndepend on the software in use and the configuration, but might include\nany of denial of service, information leak, or privilege escalation."}]}}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"unknown"}]}]},"references":{"reference_data":[{"url":"https://xenbits.xenproject.org/xsa/advisory-417.txt","refsource":"MISC","name":"https://xenbits.xenproject.org/xsa/advisory-417.txt"},{"refsource":"CONFIRM","name":"http://xenbits.xen.org/xsa/advisory-417.html","url":"http://xenbits.xen.org/xsa/advisory-417.html"},{"refsource":"MLIST","name":"[oss-security] 20221101 Xen Security Advisory 417 v2 (CVE-2022-42320) - Xenstore: Guests can get access to Xenstore nodes of deleted domains","url":"http://www.openwall.com/lists/oss-security/2022/11/01/7"},{"refsource":"DEBIAN","name":"DSA-5272","url":"https://www.debian.org/security/2022/dsa-5272"},{"refsource":"FEDORA","name":"FEDORA-2022-07438e12df","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/"},{"refsource":"FEDORA","name":"FEDORA-2022-99af00f60e","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/"},{"refsource":"FEDORA","name":"FEDORA-2022-9f51d13fa3","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/"}]},"workaround":{"workaround_data":{"description":{"description_data":[{"lang":"eng","value":"Running oxenstored instead of xenstored will avoid the vulnerability."}]}}}},"nvd":{"publishedDate":"2022-11-01 13:15:00","lastModifiedDate":"2024-02-04 08:15:00","problem_types":["CWE-459"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7,"baseSeverity":"HIGH"},"exploitabilityScore":1,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}