PT-2020-16761 · Xen+1 · Xen+1

Jann Horn

·

Published

2020-10-22

·

Updated

2024-06-15

·

CVE-2020-27674

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Xen versions through 4.14.x
Description An issue allows x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents. This is because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Recommendations For Xen versions through 4.14.x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27674
DSA-4804-1
OPENSUSE-SU-2020:2162-1
OPENSUSE-SU-2020:2192-1
OPENSUSE-SU-2020_2162-1
OPENSUSE-SU-2020_2192-1
OPENSUSE-SU-2024:11520-1
SUSE-SU-2020:14557-1
SUSE-SU-2020:3611-1
SUSE-SU-2020:3615-1
SUSE-SU-2020:3627-1
SUSE-SU-2020:3631-1
SUSE-SU-2020:3653-1
SUSE-SU-2020:3742-1
SUSE-SU-2020_14557-1

Affected Products

Suse
Xen