Description
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the same transaction, the transaction will be terminated with an error. As this error is encountered only when handling the deleted node at transaction finalization, the transaction will have been performed partially and without updating the accounting information. This will enable a malicious guest to create arbitrary number of nodes.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5272-1 | xen security update |
References
History
No history.
Status: PUBLISHED
Assigner: XEN
Published:
Updated: 2024-08-03T13:03:45.931Z
Reserved: 2022-10-03T00:00:00.000Z
Link: CVE-2022-42325
No data.
Status : Modified
Published: 2022-11-01T13:15:12.067
Modified: 2024-11-21T07:24:45.297
Link: CVE-2022-42325
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA