Xen · Xen · CVE-2020-27672
Name of the Vulnerable Software and Affected Versions:
Xen versions through 4.14.x
Description:
The issue is caused by a race condition due to incorrect synchronization when using a shared resource, allowing an attacker to cause a denial of service, achieve data corruption, or possibly gain privileges. This can be exploited by x86 guest OS users. The exploitation involves a use-after-free condition related to 2MiB and 1GiB superpages.
Recommendations:
For versions through 4.14.x, consider applying configuration changes to restrict access to shared resources until a patch is available. As a temporary workaround, limiting the use of 2MiB and 1GiB superpages may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.