Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qghj-pfv2-q8gw

Опубликовано: 01 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.

Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.

EPSS

Процентиль: 17%
0.00053
Низкий

8.8 High

CVSS3

Дефекты

CWE-763

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.

CVSS3: 8.8
nvd
больше 3 лет назад

Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.

CVSS3: 8.8
debian
больше 3 лет назад

Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-11 ...

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость хранилища информации Xenstore гипервизора Xen, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 3 лет назад

Security update for xen

EPSS

Процентиль: 17%
0.00053
Низкий

8.8 High

CVSS3

Дефекты

CWE-763