PT-2020-16114 · Xen+3 · Xen+3

Jan Beulich

·

Published

2020-09-23

·

Updated

2024-06-15

·

CVE-2020-25597

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions 4.4 through 4.14.x
Description An issue in Xen allows mishandling of event channel operations, assuming that once-valid event channels will not turn invalid. However, certain operations may decrease the bounds checked for validity, leading to bug checks and potential host crashes. This could result in a Denial of Service (DoS) for the entire system, exploitable by an unprivileged guest. The vulnerability specifically affects systems where untrusted guests can create more than the default number of event channels, which varies by architecture and guest type.
Recommendations For Xen versions 4.4 through 4.14.x, consider restricting the number of event channels that can be created by untrusted guests to the default limit, which depends on the architecture and type of guest, to minimize the risk of exploitation. As a temporary workaround, consider limiting the max event channels to 1023 for 32-bit x86 PV guests, and to 4095 for 64-bit x86 PV guests and all ARM guests, until a patch is available.

Fix

DoS

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25597
DSA-4769-1
OPENSUSE-SU-2020:1608-1
OPENSUSE-SU-2020_1608-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2020:14521-1
SUSE-SU-2020:2786-1
SUSE-SU-2020:2787-1
SUSE-SU-2020:2788-1
SUSE-SU-2020:2789-1
SUSE-SU-2020:2790-1
SUSE-SU-2020:2791-1
SUSE-SU-2020:2822-1
USN-5617-1

Affected Products

Linuxmint
Suse
Ubuntu
Xen