Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvvj-p4wf-226j

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.).

A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.).

EPSS

Процентиль: 34%
0.00141
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 8 лет назад

A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.).

CVSS3: 4.4
redhat
больше 8 лет назад

A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.).

CVSS3: 5.6
nvd
больше 8 лет назад

A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.).

CVSS3: 5.6
debian
больше 8 лет назад

A domain cleanup issue was discovered in the C xenstore daemon (aka cx ...

suse-cvrf
больше 8 лет назад

Security update for xen

EPSS

Процентиль: 34%
0.00141
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-362