← back
CVE-2022-42309

CVE-2022-42309

EPSS 0.3%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.3%KEV nãoPoC Patch referenciado
Lifecycle
01 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.
Affected products
Xen · xen

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →