CVE-2022-42330
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-42330 is a vulnerability in Xen version 4.17 that affects the Xenstore component. When a guest issues a "Soft Reset" operation (e.g., for performing a kexec), the libxl-based Xen toolstack performs an XS_RELEASE Xenstore operation. Due to a bug in xenstored, this operation can result in a crash of xenstored. The vulnerability was publicly disclosed and addressed in January 2023 (Xen Advisory).

Technical details

The vulnerability specifically affects systems using C xenstored variant in Xen 4.17. The issue occurs during the XS_RELEASE Xenstore operation, which is triggered during guest soft reset operations. Systems using the OCaml variant of xenstored and those running only PV guests (x86 only) with a libxl based toolstack are not affected by this vulnerability (Xen Advisory).

Impact

A malicious guest could exploit this vulnerability by repeatedly attempting kexec operations until triggering the xenstored bug. This would result in the inability to perform any further domain administration tasks, such as starting new guests or adding/removing resources to/from existing guests (Xen Advisory).

Mitigation and workarounds

Two mitigation options are available: 1) Using the OCaml xenstored variant instead of the C variant, or 2) Explicitly configuring guests to NOT perform the "Soft Reset" action by adding 'onsoftreset="reboot"' to the guest's configuration. However, the second option will break kexec functionality in the guest. A patch has been released to resolve the issue permanently (Xen Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12819HIGH8.1
  • NixOSNixOS
  • pgbouncer
NoYesDec 03, 2025
CVE-2025-20777MEDIUM6.7
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-65105MEDIUM5.3
  • NixOSNixOS
  • apptainer
NoYesDec 02, 2025
CVE-2025-20789MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025
CVE-2025-20788MEDIUM4.4
  • NixOSNixOS
  • android
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management