ZeroHour

CVE-2022-42309

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
Description

Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.

Vendors
xendebianfedoraproject
Products
xen, debian linux, fedora
Weakness
CWE-763
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.