CVE-2020-27671
Vulnerability Summary
Timeline
Description
An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.34%• Percentile: 28%
Affected Systems
- alpine•xen
≥ 4.2.0, < 4.12.4-r0 | ≥ 4.2.0, < 4.13.2-r0 | ≥ 4.2.0, < 4.13.2-r0 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2 | ≥ 4.2.0, < 4.14.0-r2
- debian•xen
< 4.14.0+80-gd101b417b7-1 | < 4.14.0+80-gd101b417b7-1 | < 4.14.0+80-gd101b417b7-1 | < 4.14.0+80-gd101b417b7-1
- debian•debian_linux
10.0
- fedoraproject•fedora
31
- opensuse•leap
15.1 | 15.2
- xen•xen
≥ 4.2.0, ≤ 4.14.0
References (10)
- http://xenbits.xen.org/xsa/advisory-346.html
- https://xenbits.xen.org/xsa/advisory-346.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00075.html
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00025.html
- https://security.gentoo.org/glsa/202011-06
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XIK57QJOVOPWH6RFRNMGOBCROBCKMDG2/
- https://www.debian.org/security/2020/dsa-4804
- http://www.openwall.com/lists/oss-security/2021/01/19/8
- https://security.alpinelinux.org/vuln/CVE-2020-27671
- https://security-tracker.debian.org/tracker/CVE-2020-27671