Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 37: 2022-9f51d13fa3 Critical: Xenstore Crash and Memory Issues

fedora
Calendar Grey November 23, 2022
Dist Fedora Esm H88
The latest Xen security notice highlights various speculative vulnerabilities as well as risks associated with Xenstore within the Fedora ecosystem. Ensure you're informed!
x86: Multiple speculative security issues [XSA-422, CVE-2022-23824] ---- x86: unintended memory sharing between guests [XSA-412, CVE-2022-42327] Xenstore: Guests can crash xenstore...

Summary

This package contains the XenD daemon and xm command line

tools, needed to manage virtual machines running under the

Xen hypervisor

x86: Multiple speculative security issues [XSA-422, CVE-2022-23824] ---- x86:

unintended memory sharing between guests [XSA-412, CVE-2022-42327] Xenstore:

Guests can crash xenstored [XSA-414, CVE-2022-42309] Xenstore: Guests can create

orphaned Xenstore nodes [XSA-415, CVE-2022-42310] Xenstore: guests can let run

xenstored out of memory [XSA-326, CVE-2022-42311, CVE-2022-42312,

CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317,

CVE-2022-42318] Xenstore: Guests can cause Xenstore to not free temporary memory

[XSA-416, CVE-2022-42319] Xenstore: Guests can get access to Xenstore nodes of

deleted domains [XSA-417, CVE-2022-42320] Xenstore: Guests can crash xenstored

via exhausting the stack [XSA-418, CVE-2022-42321] Xenstore: Cooperating guests

can create arbitrary numbers of nodes [XSA-419, CVE-2022-42322, CVE-2022-42323]

Oxenstored 32->31 bit integer truncation issues [XSA-420, CVE-2022-42324]

Xenstore: Guests can create arbitrary number of nodes via transactions [XSA-421,

CVE-2022-42325, CVE-2022-42326]

* Tue Nov 8 2022 Michael Young - 4.16.2-4

- x86: Multiple speculative security issues [XSA-422, CVE-2022-23824]

* Tue Nov 1 2022 Michael Young - 4.16.2-3

- x86: unintended memory sharing between guests [XSA-412, CVE-2022-42327]

- Xenstore: Guests can crash xenstored [XSA-414, CVE-2022-42309]

- Xenstore: Guests can create orphaned Xenstore nodes [XSA-415,

CVE-2022-42310]

- Xenstore: guests can let run xenstored out of memory [XSA-326,

CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314,

CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318]

- Xenstore: Guests can cause Xenstore to not free temporary memory

[XSA-416, CVE-2022-42319]

- Xenstore: Guests can get access to Xenstore nodes of deleted domains

[XSA-417, CVE-2022-42320]

- Xenstore: Guests can crash xenstored via exhausting the stack

[XSA-418, CVE-2022-42321]

- Xenstore: Cooperating guests can create arbitrary numbers of nodes

[XSA-419, CVE-2022-42322, CVE-2022-42323]

- Oxenstored 32->31 bit integer truncation issues [XSA-420, CVE-2022-42324]

- Xenstore: Guests can create arbitrary number of nodes via transactions

[XSA-421, CVE-2022-42325, CVE-2022-42326]

su -c 'dnf upgrade --advisory FEDORA-2022-9f51d13fa3' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 37
Version: 4.16.2
Release: 4.fc37
Summary: Xen is a virtual machine monitor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here