Integer overflow in Xen - CVE-2022-42336
Published: June 19, 2023
Vulnerability identifier: #VU77522
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-42336
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote guest to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in SSBD imlementation. A remote guest can mislead other guests into observing SSBD active when it is not.
Affected software
Xen
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen
xen-tools-domU
xen-libs-64bit-debuginfo
xen-libs-64bit
xen-tools-xendomains-wait-disk
xen-doc-html
xen-tools
xen-tools-debuginfo
xen-libs-32bit
xen-libs-32bit-debuginfo
xen-libs-debuginfo
xen-devel
xen-tools-domU-debuginfo
xen-libs
xen-debugsource
app-emulation/xen
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen
xen-tools-domU
xen-libs-64bit-debuginfo
xen-libs-64bit
xen-tools-xendomains-wait-disk
xen-doc-html
xen-tools
xen-tools-debuginfo
xen-libs-32bit
xen-libs-32bit-debuginfo
xen-libs-debuginfo
xen-devel
xen-tools-domU-debuginfo
xen-libs
xen-debugsource
app-emulation/xen
How to mitigate CVE-2022-42336
Install updates from vendor's website.
xen - update to 4.17.1-2.fc38
xen-tools-domU - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit - update to 4.17.1_04-150500.3.3.1
xen-tools-xendomains-wait-disk - update to 4.17.1_04-150500.3.3.1
xen-doc-html - update to 4.17.1_04-150500.3.3.1
xen - update to 4.17.1_04-150500.3.3.1
xen-tools - update to 4.17.1_04-150500.3.3.1
xen-tools-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-devel - update to 4.17.1_04-150500.3.3.1
xen-tools-domU-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs - update to 4.17.1_04-150500.3.3.1
xen-debugsource - update to 4.17.1_04-150500.3.3.1
app-emulation/xen - update to 4.17.4
xen-tools-domU - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit - update to 4.17.1_04-150500.3.3.1
xen-tools-xendomains-wait-disk - update to 4.17.1_04-150500.3.3.1
xen-doc-html - update to 4.17.1_04-150500.3.3.1
xen - update to 4.17.1_04-150500.3.3.1
xen-tools - update to 4.17.1_04-150500.3.3.1
xen-tools-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-devel - update to 4.17.1_04-150500.3.3.1
xen-tools-domU-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs - update to 4.17.1_04-150500.3.3.1
xen-debugsource - update to 4.17.1_04-150500.3.3.1
app-emulation/xen - update to 4.17.4