Denial of Service Vulnerability in Xenstore by Xen Project
CVE-2022-42314
6.5MEDIUM
What is CVE-2022-42314?
The vulnerability in Xenstore allows malicious guests to exploit memory management by issuing requests without processing responses, leading to excessive memory allocation. This can result in a Denial of Service (DoS) attack by overflowing the xenstored service. Attackers can trigger large memory consumption through various means, such as creating numerous watch events, generating multiple nodes with maximum size, or making extensive access within transactions. The consequences are detrimental for overall system availability, as they can effectively cripple xenstored by exhausting its memory resources.
Affected Version(s)
xen consult Xen advisory XSA-326
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
{'credit_data': {'description': {'description_data': [{'lang': 'eng', 'value': 'This issue was discovered by Julien Grall of Amazon.'}]}}}