VDB
CVE-2022-42319
CVE-2022-42319
PUBLISHED
In Xen und Citrix Systems Hypervisor existieren mehrere Schwachstellen. Ein Angreifer kann diese Schwachstellen ausnutzen, um einen Denial of Service zu verursachen, Informationen offenzulegen oder seine Rechte zu erweitern. Zur Ausnutzung einiger Schwachstellen ist eine Anmeldung mit erweiterten Rechten erforderlich.
EPSS 0.03% · 8.9th percentile
Risk Scores
EPSS Score
0.03%
8.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citrix Systems | Citrix Systems Hypervisor 8.2 LTSR CU1 | |
| Gentoo | Gentoo Linux | |
| Debian | Debian Linux | |
| Open Source | Open Source Xen 4.15.x | |
| SUSE | SUSE Linux | |
| Open Source | Open Source Xen 4.16.x | |
| Open Source | Open Source Xen 4.13.x |
Exploit Intelligence
- https://xenbits.xenproject.org/xsa/advisory-416.txt (circl)
- http://xenbits.xen.org/xsa/advisory-416.html (circl)
- [oss-security] 20221101 Xen Security Advisory 416 v2 (CVE-2022-42319) - Xenstore: Guests can cause Xenstore to not free temporary memory (circl)
- DSA-5272 (circl)
- FEDORA-2022-07438e12df (circl)
- FEDORA-2022-99af00f60e (circl)
- FEDORA-2022-9f51d13fa3 (circl)
- GLSA-202402-07 (circl)
Timeline
- Nov 1, 2022 CVE Published
- Nov 2, 2022 EPSS Score
- Dec 15, 2022 EPSS Score
- Jan 28, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 12, 2023 EPSS Score
- Apr 24, 2023 EPSS Score
- Jun 6, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
- Sep 1, 2023 EPSS Score
- Oct 14, 2023 EPSS Score
- Nov 26, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-1939.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1939 advisory
- https://xenbits.xen.org/xsa/advisory-412.html advisory
- https://xenbits.xen.org/xsa/advisory-413.html advisory
- https://xenbits.xen.org/xsa/advisory-414.html advisory
- https://xenbits.xen.org/xsa/advisory-415.html advisory
- https://xenbits.xen.org/xsa/advisory-416.html advisory
- https://xenbits.xen.org/xsa/advisory-417.html advisory
- https://xenbits.xen.org/xsa/advisory-418.html advisory
- https://xenbits.xen.org/xsa/advisory-419.html advisory
- https://xenbits.xen.org/xsa/advisory-420.html advisory
- https://xenbits.xen.org/xsa/advisory-421.html advisory
- https://support.citrix.com/article/CTX472851/citrix-hypervisor-security-bulletin-for-cve202242316-cve202242317-cve202242318 advisory
- https://xenbits.xen.org/xsa/advisory-326.html advisory
- https://lists.debian.org/debian-security-announce/2022/msg00242.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2022-November/012859.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2022-November/012866.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2022-November/012906.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2022-November/012903.html advisory
- https://lists.suse.com/pipermail/sle-security-updates/2022-November/012910.html advisory
…and 6 more