PT-2020-12820 · Xen+3 · Xen+3

Jürgen Groß

+1

·

Published

2020-04-14

·

Updated

2024-06-15

·

CVE-2020-11742

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.14
Description An issue in Xen allows guest OS users to cause a denial of service due to bad continuation handling in GNTTABOP copy. Grant table operations are expected to return 0 for success and a negative number for errors. However, a path through grant copy handling may return success to the caller without any action taken, leaving status fields of individual operations uninitialised. This can result in errant behaviour in the caller of GNTTABOP copy. A buggy or malicious guest can construct its grant table to hit the incorrect exit path when a backend domain tries to copy a grant, returning success without doing anything, which may cause crashes or other incorrect behaviour.
Recommendations For Xen versions prior to 4.14, update to version 4.14 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-11742
DSA-4723-1
OPENSUSE-SU-2020:0599-1
OPENSUSE-SU-2020_0599-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2020:1124-1
SUSE-SU-2020:1138-1
SUSE-SU-2020:1139-1
SUSE-SU-2020:14444-1
SUSE-SU-2020:14448-1
SUSE-SU-2020:1630-1
SUSE-SU-2020:1634-1
SUSE-SU-2020:2234-1
SUSE-SU-2020_1630-1
SUSE-SU-2020_1634-1
USN-5617-1

Affected Products

Linuxmint
Suse
Ubuntu
Xen