CVE-2022-42326

Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the same transaction, the transaction will be terminated with an error. As this error is encountered only when handling the deleted node at transaction finalization, the transaction will have been performed partially and without updating the accounting information. This will enable a malicious guest to create arbitrary number of nodes.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

History

21 Nov 2024, 07:24

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2022/11/01/11 - Mailing List, Patch, Third Party Advisory () http://www.openwall.com/lists/oss-security/2022/11/01/11 - Mailing List, Patch, Third Party Advisory
References () http://xenbits.xen.org/xsa/advisory-421.html - Patch, Vendor Advisory () http://xenbits.xen.org/xsa/advisory-421.html - Patch, Vendor Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/ -
References () https://security.gentoo.org/glsa/202402-07 - () https://security.gentoo.org/glsa/202402-07 -
References () https://www.debian.org/security/2022/dsa-5272 - Third Party Advisory () https://www.debian.org/security/2022/dsa-5272 - Third Party Advisory
References () https://xenbits.xenproject.org/xsa/advisory-421.txt - Patch, Vendor Advisory () https://xenbits.xenproject.org/xsa/advisory-421.txt - Patch, Vendor Advisory

29 Nov 2022, 18:29

Type Values Removed Values Added
CPE cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/ - Mailing List, Third Party Advisory

24 Nov 2022, 03:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YTMITQBGC23MSDHUCAPCVGLMVXIBXQTQ/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZVXG7OOOXCX6VIPEMLFDPIPUTFAYWPE/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/ - Mailing List, Third Party Advisory
References (DEBIAN) https://www.debian.org/security/2022/dsa-5272 - (DEBIAN) https://www.debian.org/security/2022/dsa-5272 - Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

09 Nov 2022, 14:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLI2NPNEH7CNJO3VZGQNOI4M4EWLNKPZ/ -

07 Nov 2022, 08:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2022/dsa-5272 -

03 Nov 2022, 17:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References (MISC) https://xenbits.xenproject.org/xsa/advisory-421.txt - (MISC) https://xenbits.xenproject.org/xsa/advisory-421.txt - Patch, Vendor Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/11/01/11 - (MLIST) http://www.openwall.com/lists/oss-security/2022/11/01/11 - Mailing List, Patch, Third Party Advisory
References (CONFIRM) http://xenbits.xen.org/xsa/advisory-421.html - (CONFIRM) http://xenbits.xen.org/xsa/advisory-421.html - Patch, Vendor Advisory
CWE CWE-401
CPE cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*

01 Nov 2022, 15:15

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/11/01/11 -
  • (CONFIRM) http://xenbits.xen.org/xsa/advisory-421.html -

01 Nov 2022, 13:38

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-01 13:15

Updated : 2024-11-21 07:24


NVD link : CVE-2022-42326

Mitre link : CVE-2022-42326

CVE.ORG link : CVE-2022-42326


JSON object : View

Products Affected

fedoraproject

  • fedora

xen

  • xen

debian

  • debian_linux
CWE
CWE-401

Missing Release of Memory after Effective Lifetime