Oval Definition:oval:org.opensuse.security:def:202242320
Revision Date:2023-06-22Version:1
Title:CVE-2022-42320
Description:

Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time window when a new domain is created, where the access rights of a past domain with the same domid as the new one will be regarded to be still valid, leading to the new domain being able to get access to a node which was meant to be accessible by the removed domain. For this to happen another domain needs to write the node before the newly created domain is being introduced to Xenstore by dom0.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-42320
SUSE CVE-2022-42320
SUSE-IU-2022:1124-1
SUSE-IU-2022:1130-1
SUSE-IU-2022:1131-1
SUSE-IU-2022:1132-1
SUSE-IU-2022:1133-1
SUSE-IU-2022:1134-1
SUSE-IU-2022:1148-1
SUSE-SU-2022:3925-1
SUSE-SU-2022:3928-1
SUSE-SU-2022:3947-1
SUSE-SU-2022:3960-1
SUSE-SU-2022:3971-1
SUSE-SU-2022:4007-1
SUSE-SU-2022:4051-1
SUSE-SU-2022:4241-1
SUSE-SU-2022:4332-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND xen-libs-4.16.2_08-150400.4.16.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • xen-libs-4.17.0_06-150500.1.10 is installed
  • OR xen-tools-domU-4.17.0_06-150500.1.10 is installed
  • BACK