Untrusted Pointer Dereference in Xen - CVE-2022-42335
Published: April 25, 2023
Vulnerability identifier: #VU75481
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2022-42335
CWE-ID: CWE-822
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a malicious guest to escalate privileges on the system.
The vulnerability exists due to an arbitrary pointer dereference. A malicious guest running in shadow mode and having a PCI device passed through can execute arbitrary code on the hypervisor.
Affected software
Xen
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen
xen-debugsource
xen-tools-domU
xen-libs
xen-tools-domU-debuginfo
xen-devel
xen-libs-debuginfo
xen-libs-32bit-debuginfo
xen-libs-32bit
xen-tools-debuginfo
xen-tools
xen-doc-html
xen-tools-xendomains-wait-disk
xen-libs-64bit
xen-libs-64bit-debuginfo
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen
xen-debugsource
xen-tools-domU
xen-libs
xen-tools-domU-debuginfo
xen-devel
xen-libs-debuginfo
xen-libs-32bit-debuginfo
xen-libs-32bit
xen-tools-debuginfo
xen-tools
xen-doc-html
xen-tools-xendomains-wait-disk
xen-libs-64bit
xen-libs-64bit-debuginfo
How to mitigate CVE-2022-42335
Install updates from vendor's website.
xen - update to 4.17.0-9.fc38
xen-debugsource - update to 4.17.1_04-150500.3.3.1
xen-tools-domU - update to 4.17.1_04-150500.3.3.1
xen-libs - update to 4.17.1_04-150500.3.3.1
xen-tools-domU-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-devel - update to 4.17.1_04-150500.3.3.1
xen-libs-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit - update to 4.17.1_04-150500.3.3.1
xen-tools-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-tools - update to 4.17.1_04-150500.3.3.1
xen - update to 4.17.1_04-150500.3.3.1
xen-doc-html - update to 4.17.1_04-150500.3.3.1
xen-tools-xendomains-wait-disk - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-debugsource - update to 4.17.1_04-150500.3.3.1
xen-tools-domU - update to 4.17.1_04-150500.3.3.1
xen-libs - update to 4.17.1_04-150500.3.3.1
xen-tools-domU-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-devel - update to 4.17.1_04-150500.3.3.1
xen-libs-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit - update to 4.17.1_04-150500.3.3.1
xen-tools-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-tools - update to 4.17.1_04-150500.3.3.1
xen - update to 4.17.1_04-150500.3.3.1
xen-doc-html - update to 4.17.1_04-150500.3.3.1
xen-tools-xendomains-wait-disk - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit-debuginfo - update to 4.17.1_04-150500.3.3.1