PT-2020-6761 · Xen · Xen

Edwin Török

·

Published

2020-12-15

·

Updated

2022-04-26

·

CVE-2020-29479

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xen versions prior to 4.14.x
Description The issue is related to the implementation of Ocaml xenstored in Xen, where the internal representation of the tree has special cases for the root node. Unfortunately, permissions were not checked for certain operations on the root node, allowing unprivileged guests to get and modify permissions, list, and delete the root node. This can lead to a host-wide denial of service if the whole xenstore tree is deleted. Achieving xenstore write access is also possible. All systems using oxenstored are vulnerable, while systems using C xenstored are not.
Recommendations For Xen versions prior to 4.14.x, consider disabling the use of oxenstored as a temporary workaround until a patch is available. Restrict access to the xenstore tree to minimize the risk of exploitation. Avoid using the oxenstored implementation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06104
CVE-2020-29479
DSA-4812-1

Affected Products

Xen