CVE-2022-42309EPSS p18.7%
CVE-2022-42309CVE-2022-42309
xen / xen
Description
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.27% probability of exploitation · percentile 18.7% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |