Xen Xenstore DomID ACL Leak from Deleted Domains
CVE-2022-42320 Published on November 1, 2022
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time window when a new domain is created, where the access rights of a past domain with the same domid as the new one will be regarded to be still valid, leading to the new domain being able to get access to a node which was meant to be accessible by the removed domain. For this to happen another domain needs to write the node before the newly created domain is being introduced to Xenstore by dom0.
Products Associated with CVE-2022-42320
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-42320 are published in these products:
Affected Versions
xen Version consult Xen advisory XSA-417 is unknown by CVE-2022-42320Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.