CVE-2023-34323: Xen
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
When a transaction is committed, C Xenstored will first check the quota is correct before attempting to commit any nodes. It would be possible that accounting is temporarily negative if a node has been removed outside of the transaction. Unfortunately, some versions of C Xenstored are assuming that the quota cannot be negative and are using assert() to confirm it. This will lead to C Xenstored crash when tools are built without -DNDEBUG (this is the default).
Affected products
- Xen Xen: before 4.17.0 (fixed in 4.17.0)
Published 2024-01-05. Last modified 2026-06-17.