7.5
CVSSv3

CVE-2022-42330

Published: 26/01/2023 Updated: 06/02/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9

Vulnerability Summary

Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libxl based Xen toolstack will normally perform a XS_RELEASE Xenstore operation. Due to a bug in xenstored this can result in a crash of xenstored. Any other use of XS_RELEASE will have the same impact.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.17.0

Vendor Advisories

Debian Bug report logs - #1029830 xen: CVE-2022-42330 Package: src:xen; Maintainer for src:xen is Debian Xen Team <pkg-xen-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 28 Jan 2023 13:03:04 UTC Severity: important Tags: security, upstream Found in version xen/4170 ...

Github Repositories

CVE-2022-42330 Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (eg for performing a kexec) the libxl based Xen toolstack will normally perform a XS_RELEASE Xenstore operation Due to a bug in xenstored this can result in a crash of xenstored Any other use of XS_RELEASE will have the same impact authentication complexity vector