SUSE-SU-2022:4007-1

    Dashboard / Vulnerabilities / SUSE-SU-2022:4007-1

    SUSE-SU-2022:4007-1

    Published: 16 Nov 2022Last Modified: 4 Feb 2026

    Summary: Security update for xen

    Details: This update for xen fixes the following issues: - CVE-2022-33746: Fixed DoS due to excessively long P2M pool freeing (bsc#1203806). - CVE-2022-33748: Fixed DoS due to race in locking (bsc#1203807). - CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318: xen: Xenstore: Guests can let xenstored run out of memory (bsc#1204482) - CVE-2022-42309: xen: Xenstore: Guests can crash xenstored (bsc#1204485) - CVE-2022-42310: xen: Xenstore: Guests can create orphaned Xenstore nodes (bsc#1204487) - CVE-2022-42319: xen: Xenstore: Guests can cause Xenstore to not free temporary memory (bsc#1204488) - CVE-2022-42320: xen: Xenstore: Guests can get access to Xenstore nodes of deleted domains (bsc#1204489) - CVE-2022-42321: xen: Xenstore: Guests can crash xenstored via exhausting the stack (bsc#1204490) - CVE-2022-42322,CVE-2022-42323: xen: Xenstore: cooperating guests can create arbitrary numbers of nodes (bsc#1204494) - CVE-2022-42325,CVE-2022-42326: xen: Xenstore: Guests can create arbitrary number of nodes via transactions (bsc#1204496) - xen: Frontends vulnerable to backends (bsc#1193923).

    References: https://www.suse.com/support/update/announcement/2022/suse-su-20224007-1/, https://bugzilla.suse.com/1027519, https://bugzilla.suse.com/1193923, https://bugzilla.suse.com/1203806, https://bugzilla.suse.com/1203807, https://bugzilla.suse.com/1204482, https://bugzilla.suse.com/1204483, https://bugzilla.suse.com/1204485, https://bugzilla.suse.com/1204487, https://bugzilla.suse.com/1204488, https://bugzilla.suse.com/1204489, https://bugzilla.suse.com/1204490, https://bugzilla.suse.com/1204494, https://bugzilla.suse.com/1204496, https://www.suse.com/security/cve/CVE-2022-33746, https://www.suse.com/security/cve/CVE-2022-33747, https://www.suse.com/security/cve/CVE-2022-33748, https://www.suse.com/security/cve/CVE-2022-42309, https://www.suse.com/security/cve/CVE-2022-42310, https://www.suse.com/security/cve/CVE-2022-42311, https://www.suse.com/security/cve/CVE-2022-42312, https://www.suse.com/security/cve/CVE-2022-42313, https://www.suse.com/security/cve/CVE-2022-42314, https://www.suse.com/security/cve/CVE-2022-42315, https://www.suse.com/security/cve/CVE-2022-42316, https://www.suse.com/security/cve/CVE-2022-42317, https://www.suse.com/security/cve/CVE-2022-42318, https://www.suse.com/security/cve/CVE-2022-42319, https://www.suse.com/security/cve/CVE-2022-42320, https://www.suse.com/security/cve/CVE-2022-42321, https://www.suse.com/security/cve/CVE-2022-42322, https://www.suse.com/security/cve/CVE-2022-42323, https://www.suse.com/security/cve/CVE-2022-42325, https://www.suse.com/security/cve/CVE-2022-42326, https://www.suse.com/security/cve/CVE-2022-42327

    Affected packages

    Package

    Name: xen

    Purl: pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Micro%205.3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.16.2_08-150400.4.16.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2022:4007-1 | CVE-DB