Denial of Service Vulnerability in Xenstore by Xen Project
CVE-2022-42316

6.5MEDIUM

Key Information:

Vendor
CVE Published:
1 November 2022

What is CVE-2022-42316?

The vulnerability in Xenstore allows malicious guests to exhaust memory resources by manipulating request handling. Attackers can issue numerous requests without processing responses, leading to excessive memory buffering. Furthermore, they can generate significant numbers of watch events through repeated node deletions or by creating maximum-sized nodes within transactions. This can culminate in a Denial of Service situation, incapacitating the xenstored service, thereby impacting the stability and availability of the virtual environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

xen consult Xen advisory XSA-326

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

{'credit_data': {'description': {'description_data': [{'lang': 'eng', 'value': 'This issue was discovered by Julien Grall of Amazon.'}]}}}
.