Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2022:4332-1 Critical: Resolve Memory Problems in Xen Environment

suse
Calendar Grey December 6, 2022
Dist Suse Esm H88
Canonical has issued a vital security patch for the Linux kernel addressing significant vulnerabilities such as buffer overflows and system failures. Remain protected!
An update that fixes 17 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318: xen: Xenstore: Guests can let xenstored run out of memory (bsc#1204482) - CVE-2022-42309: xen: Xenstore: Guests can crash xenstored (bsc#1204485) - CVE-2022-42310: xen: Xenstore: Guests can create orphaned Xenstore nodes (bsc#1204487) - CVE-2022-42319: xen: Xenstore: Guests can cause Xenstore to not free temporary memory (bsc#1204488) - CVE-2022-42320: xen: Xenstore: Guests can get access to Xenstore nodes of deleted domains (bsc#1204489) - CVE-2022-42321: xen: Xenstore: Guests can crash xenstored via exhausting the stack (bsc#1204490) - CVE-2022-42322,CVE-2022-42323: xen: Xenstore: cooperating guests can

References

#1193923 #1203806 #1204482 #1204485 #1204487

#1204488 #1204489 #1204490 #1204494 #1204496

Cross- CVE-2022-42309 CVE-2022-42310 CVE-2022-42311

CVE-2022-42312 CVE-2022-42313 CVE-2022-42314

CVE-2022-42315 CVE-2022-42316 CVE-2022-42317

CVE-2022-42318 CVE-2022-42319 CVE-2022-42320

CVE-2022-42321 CVE-2022-42322 CVE-2022-42323

CVE-2022-42325 CVE-2022-42326

CVSS scores:

CVE-2022-42309 (NVD) : 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2022-42309 (SUSE): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CVE-2022-42310 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2022-42310 (SUSE): 6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

CVE-2022-42311 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:4332-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here