PT-2020-16117 · Xen+3 · Xen+3

Julien Grall

·

Published

2020-09-23

·

Updated

2024-06-15

·

CVE-2020-25600

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions 4.4 through 4.14.x
Description An issue in Xen allows out of bounds event channels to be available to 32-bit x86 domains. This is due to a misbehavior in the recording of event channel limits during domain initialization. As a result, 32-bit domains may observe event channel allocations to succeed when they should fail, leading to potential corruption of the shared info structure. An unprivileged guest may cause another domain, including Domain 0, to misbehave, resulting in a Denial of Service (DoS) for the entire system.
Recommendations For Xen versions 4.4 through 4.14.x, consider disabling the use of event channels for 32-bit x86 domains servicing other domains until a patch is available. Restrict access to the shared info structure to minimize the risk of corruption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25600
DSA-4769-1
OPENSUSE-SU-2020:1608-1
OPENSUSE-SU-2020_1608-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2020:14521-1
SUSE-SU-2020:2786-1
SUSE-SU-2020:2787-1
SUSE-SU-2020:2788-1
SUSE-SU-2020:2789-1
SUSE-SU-2020:2790-1
SUSE-SU-2020:2791-1
SUSE-SU-2020:2822-1
USN-5617-1

Affected Products

Linuxmint
Suse
Ubuntu
Xen