← Back

CVE-2022-42310

nvd nist
Published: Nov 1, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes already created. When the transaction is committed after this situation, nodes without a valid parent can be made permanent in the data base.

Affected (5)

1 product
Xen
1 product
Debian Linux
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.9.0 to 4.13.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Fedoraproject
Version 35
Version 36
Version 37

References (16)

Source: security@xen.org
Mailing ListThird Party Advisory
Source: security@xen.org
PatchThird Party Advisory
Source: security@xen.org
Third Party Advisory
Source: security@xen.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.