CVE-2022-42320
Last modified
CVE-2022-42320 is a high-severity vulnerability rated 7/10 on the CVSS scale. Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time window when a new domain is created, where the access rights of a past domain with the same domid as the new one will be regarded to be still valid, leading to the new domain being able to get access to a node which was meant to be accessible by the removed domain. For this to happen another domain needs to write the node before the newly created domain is being introduced to Xenstore by dom0.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | All versions |
| Debian | Debian Linux | 11.0 |
| Fedoraproject | Fedora | 35 |
| Fedoraproject | Fedora | 36 |
| Fedoraproject | Fedora | 37 |
References
- http://www.openwall.com/lists/oss-security/2022/11/01/7Mailing List, Third Party Advisory
- http://xenbits.xen.org/xsa/advisory-417.htmlPatch, Vendor Advisory
- https://www.debian.org/security/2022/dsa-5272Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-417.txtPatch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2022/11/01/7Mailing List, Third Party Advisory
- http://xenbits.xen.org/xsa/advisory-417.htmlPatch, Vendor Advisory
- https://www.debian.org/security/2022/dsa-5272Third Party Advisory
- https://xenbits.xenproject.org/xsa/advisory-417.txtPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-42320?
How severe is CVE-2022-42320?
How do I fix CVE-2022-42320?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-42315Xenstore: guests can let run xenstored out of memory T[his C…6.5
- CVE-2022-42316Xenstore: guests can let run xenstored out of memory T[his C…6.5
- CVE-2022-42317Xenstore: guests can let run xenstored out of memory T[his C…6.5
- CVE-2022-42318Xenstore: guests can let run xenstored out of memory T[his C…6.5
- CVE-2022-42319Xenstore: Guests can cause Xenstore to not free temporary me…6.5
- CVE-2022-4232A vulnerability, which was classified as critical, was found…9.8
- CVE-2022-42321Xenstore: Guests can crash xenstored via exhausting the stac…6.5
- CVE-2022-42322Xenstore: Cooperating guests can create arbitrary numbers of…5.5
- CVE-2022-42323Xenstore: Cooperating guests can create arbitrary numbers of…5.5
- CVE-2022-42324Oxenstored 32->31 bit integer truncation issues Integers in …5.5
- CVE-2022-42325Xenstore: Guests can create arbitrary number of nodes via tr…5.5
- CVE-2022-42326Xenstore: Guests can create arbitrary number of nodes via tr…5.5
Are you affected by CVE-2022-42320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
