CVE-2022-42309
8.8
HIGH
CVSS 3.1
EPSS 0.06%
Description
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.
How to fix CVE-2022-42309
To remediate CVE-2022-42309, upgrade the affected package to a fixed version below.
- —upgrade to 4.14.5-r6 or later
- —upgrade to 4.14.5+86-g1c354767d5-1 or later
Is CVE-2022-42309 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 4.14.5-r6
- from 0, < 4.14.5+86-g1c354767d5-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |