Integer overflow in Xen - CVE-2022-42336

 

Integer overflow in Xen - CVE-2022-42336

Published: June 19, 2023


Vulnerability identifier: #VU77522
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-42336
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote guest to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow in SSBD imlementation. A remote guest can mislead other guests into observing SSBD active when it is not.


Affected software

Xen
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen
xen-tools-domU
xen-libs-64bit-debuginfo
xen-libs-64bit
xen-tools-xendomains-wait-disk
xen-doc-html
xen-tools
xen-tools-debuginfo
xen-libs-32bit
xen-libs-32bit-debuginfo
xen-libs-debuginfo
xen-devel
xen-tools-domU-debuginfo
xen-libs
xen-debugsource
app-emulation/xen

How to mitigate CVE-2022-42336

Install updates from vendor's website.

xen - update to 4.17.1-2.fc38
xen-tools-domU - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-64bit - update to 4.17.1_04-150500.3.3.1
xen-tools-xendomains-wait-disk - update to 4.17.1_04-150500.3.3.1
xen-doc-html - update to 4.17.1_04-150500.3.3.1
xen - update to 4.17.1_04-150500.3.3.1
xen-tools - update to 4.17.1_04-150500.3.3.1
xen-tools-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit - update to 4.17.1_04-150500.3.3.1
xen-libs-32bit-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-devel - update to 4.17.1_04-150500.3.3.1
xen-tools-domU-debuginfo - update to 4.17.1_04-150500.3.3.1
xen-libs - update to 4.17.1_04-150500.3.3.1
xen-debugsource - update to 4.17.1_04-150500.3.3.1
app-emulation/xen - update to 4.17.4

External References

Related Security Bulletins