Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hongyan Xia

Researcher fromAmazon
#39288of 53,633
7Total CVSS
Vulnerabilities · 1
PT-2020-4728
7.0
2020-10-20
Xen · Xen · CVE-2020-27672
Name of the Vulnerable Software and Affected Versions: Xen versions through 4.14.x Description: The issue is caused by a race condition due to incorrect synchronization when using a shared resource, allowing an attacker to cause a denial of service, achieve data corruption, or possibly gain privileges. This can be exploited by x86 guest OS users. The exploitation involves a use-after-free condition related to 2MiB and 1GiB superpages. Recommendations: For versions through 4.14.x, consider applying configuration changes to restrict access to shared resources until a patch is available. As a temporary workaround, limiting the use of 2MiB and 1GiB superpages may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.