PT-2020-6151 · Xen · Xen

Edwin Török

·

Published

2020-12-15

·

Updated

2021-12-10

·

CVE-2020-29486

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.14.x
Description The issue is related to the oxenstored process of the Xen hypervisor, which is associated with unbounded memory allocation. Exploitation of this issue can allow an attacker to cause a denial of service. In oxenstored, a node owner could give a node away, but node ownership has quota implications. Any guest can run another guest out of quota or create an unbounded number of nodes owned by dom0, thus running xenstored out of memory. A malicious guest administrator can cause a denial of service against a specific guest or against the whole host. All systems using oxenstored are vulnerable.
Recommendations For Xen versions prior to 4.14.x, consider disabling the use of oxenstored as a temporary workaround until a patch is available. Restrict access to the xenstore nodes to minimize the risk of exploitation. Avoid using the oxenstored process in the upstream Xen distribution if the Ocaml compiler is available, and instead use C xenstored, which is not vulnerable.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03185
CVE-2020-29486
DSA-4812-1

Affected Products

Xen