Denial of Service Vulnerability in Xenstore from Xen Project
CVE-2022-42317

6.5MEDIUM

Key Information:

Vendor
CVE Published:
1 November 2022

What is CVE-2022-42317?

This vulnerability in Xenstore allows malicious guests to exploit memory allocation flaws, potentially leading to a Denial of Service (DoS). Attackers can induce excessive memory use by flooding the xenstored process with requests, preventing it from managing memory efficiently. Techniques include issuing multiple unhandled requests, generating numerous watch events, creating excessive nodes, and accessing multiple nodes simultaneously within a transaction. This improper memory management can disrupt Xenstore's functionality, weakening overall system stability.

Affected Version(s)

xen consult Xen advisory XSA-326

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

{'credit_data': {'description': {'description_data': [{'lang': 'eng', 'value': 'This issue was discovered by Julien Grall of Amazon.'}]}}}
.