Untrusted Pointer Dereference in Xen - CVE-2022-42335

 

Untrusted Pointer Dereference in Xen - CVE-2022-42335

Published: April 25, 2023


Vulnerability identifier: #VU75481
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2022-42335
CWE-ID: CWE-822
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a malicious guest to escalate privileges on the system.

The vulnerability exists due to an arbitrary pointer dereference. A malicious guest running in shadow mode and having a PCI device passed through can execute arbitrary code on the hypervisor.


Affected software

Xen
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen
xen-debugsource
xen-tools-domU
xen-libs
xen-tools-domU-debuginfo
xen-devel
xen-libs-debuginfo
xen-libs-32bit-debuginfo
xen-libs-32bit
xen-tools-debuginfo
xen-tools
xen-doc-html
xen-tools-xendomains-wait-disk
xen-libs-64bit
xen-libs-64bit-debuginfo

How to mitigate CVE-2022-42335

Install updates from vendor's website.

xen - update to 4.17.0-9.fc38
xen-debugsource - update to 4.17.1_04-150500.3.3.1
xen-tools-domU - update to 4.17.1_04-150500.3.3.1
xen-libs - update to 4.17.1_04-150500.3.3.1
xen-tools-domU-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-devel - update to 4.17.1_04-150500.3.3.1
xen-libs-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit - update to 4.17.1_04-150500.3.3.1
xen-tools-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-tools - update to 4.17.1_04-150500.3.3.1
xen - update to 4.17.1_04-150500.3.3.1
xen-doc-html - update to 4.17.1_04-150500.3.3.1
xen-tools-xendomains-wait-disk - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit-debuginfo - update to 4.17.1_04-150500.3.3.1

External References

Related Security Bulletins