← back
CVE-2022-42330

CVE-2022-42330

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.4%
exploitation probability
1.4%top 30% of all CVEs
observed exploitation
nono source reports it
In short

A guest system can crash the Xenstore (a critical shared storage system in Xen) by performing a soft reset or using certain operations. This is dangerous because it affects all virtual machines on the same host.

Technical detail

The Xenstore daemon crashes when processing XS_RELEASE operations, triggered by guest-initiated soft resets or direct XS_RELEASE calls. The vulnerability exists in xenstored's handling of this operation, allowing any guest with Xenstore access to cause a denial of service affecting the hypervisor's control plane.

Summary generated and translated by AI from the official description.
Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libxl based Xen toolstack will normally perform a XS_RELEASE Xenstore operation. Due to a bug in xenstored this can result in a crash of xenstored. Any other use of XS_RELEASE will have the same impact.
Affected products
Xen · xen