PT-2020-4728 · Xen+1 · Xen+1
Hongyan Xia
·
Published
2020-10-20
·
Updated
2024-06-15
·
CVE-2020-27672
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Xen versions through 4.14.x
Description:
The issue is caused by a race condition due to incorrect synchronization when using a shared resource, allowing an attacker to cause a denial of service, achieve data corruption, or possibly gain privileges. This can be exploited by x86 guest OS users. The exploitation involves a use-after-free condition related to 2MiB and 1GiB superpages.
Recommendations:
For versions through 4.14.x, consider applying configuration changes to restrict access to shared resources until a patch is available. As a temporary workaround, limiting the use of 2MiB and 1GiB superpages may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Xen