Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction
References
Link | Resource |
---|---|
https://xenbits.xenproject.org/xsa/advisory-326.txt | Patch Vendor Advisory |
http://xenbits.xen.org/xsa/advisory-326.html | Patch Vendor Advisory |
https://www.debian.org/security/2022/dsa-5272 | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/ | Mailing List Third Party Advisory |
Configurations
Information
Published : 2022-11-01 06:15
Updated : 2022-12-12 12:00
NVD link : CVE-2022-42312
Mitre link : CVE-2022-42312
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
debian
- debian_linux
xen
- xen
fedoraproject
- fedora