#VU80924 Resource management error in Xen - CVE-2023-34322

 

#VU80924 Resource management error in Xen - CVE-2023-34322

Published: September 20, 2023


Vulnerability identifier: #VU80924
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-34322
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Xen
Software vendor:
Xen Project

Description

The vulnerability allows a malicious guest to escalate privileges on the system.

The vulnerability exists due to improper management of internal resources when running PV guests in shadow paging mode. A malicious guest can run a specially crafted application on the system that causes shortage of memory in the associated with the domain shadow pool and forces Xen to tear down page tables. This can result in memory leak, denial of service or privilege escalation.

The vulnerability can be exploited by 64-bit PV guests on x86 systems.


Remediation

Install updates from vendor's website.

External links