CVE-2022-42317
- EPSS 0.07%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 05.05.2025 20:15:18
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of mem...
CVE-2022-42318
- EPSS 0.06%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 05.05.2025 17:18:18
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of mem...
CVE-2022-42319
- EPSS 0.03%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:44
Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quite large amounts of memory temporarily. This memory is freed only after the request has been finished completel...
- EPSS 0.04%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:44
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is norma...
CVE-2022-42321
- EPSS 0.03%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:44
Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g. for deleting a sub-tree of Xenstore nodes). With sufficiently deep nesting levels this can result in stack exhaustion on xen...
CVE-2022-42322
- EPSS 0.03%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:44
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a ...
CVE-2022-42323
- EPSS 0.03%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:45
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a ...
CVE-2022-33746
- EPSS 0.03%
- Veröffentlicht 11.10.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:27
P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking ...
CVE-2022-33747
- EPSS 0.03%
- Veröffentlicht 11.10.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:27
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal oper...
CVE-2022-33748
- EPSS 0.03%
- Veröffentlicht 11.10.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:27
lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each...