Severity
7.8HIGHNVD
OSV5.5
EPSS
0.1%
top 74.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateSep 19

Description

An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a processor is allowed to re-order the memory access with the preceding ones. In other words, the unlock may be seen by another processor before all the memory accesses within the "critical" section. As a consequence, it may be po

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.1 | Impact: 6.0

Affected Packages4 packages

Debianxen/xen< 4.11.4-1+3
Ubuntuxen/xen< 4.11.3+24-g14b62ab3e5-1ubuntu2.3
NVDxen/xen4.13.0+1
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, Fedora 30, 31, 32

Patches

🔴Vulnerability Details

4
OSV
xen vulnerabilities2022-09-19
GHSA
GHSA-5wwp-3576-jfjc: An issue was discovered in Xen through 42022-05-24
OSV
CVE-2020-11739: An issue was discovered in Xen through 42020-04-14
CVEList
CVE-2020-11739: An issue was discovered in Xen through 42020-04-14

📋Vendor Advisories

3
Ubuntu
Xen vulnerabilities2022-09-19
Red Hat
xen: missing memory barriers in read-write unlock paths (XSA-314)2020-04-14
Debian
CVE-2020-11739: xen - An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause ...2020

💬Community

2
Bugzilla
CVE-2020-11739 xen: missing memory barriers in read-write unlock paths (XSA-314) [fedora-all]2020-04-14
Bugzilla
CVE-2020-11739 xen: missing memory barriers in read-write unlock paths (XSA-314)2020-04-14
CVE-2020-11739 — Race Condition in XEN | cvebase