Denial of Service in Xenstore Affects Xen Project
CVE-2022-42313
6.5MEDIUM
What is CVE-2022-42313?
Xenstore, a key component of the Xen hypervisor, is susceptible to attacks that can lead to a Denial of Service (DoS). Malicious guests can exploit this vulnerability by inducing xenstored to allocate excessive memory, eventually overwhelming the service. Common attack vectors include sending numerous requests without processing responses, generating a significant volume of watch events, creating maximal nodes simultaneously, and accessing numerous nodes within transactions. These tactics can exhaust system resources, leading to interruptions in services relying on xenstored.
Affected Version(s)
xen consult Xen advisory XSA-326
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
{'credit_data': {'description': {'description_data': [{'lang': 'eng', 'value': 'This issue was discovered by Julien Grall of Amazon.'}]}}}