cbcvebase.
CVE-2020-11739
published 2020-04-14

CVE-2020-11739: An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory…

PriorityP337high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.29%
20.7th percentile
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a processor is allowed to re-order the memory access with the preceding ones. In other words, the unlock may be seen by another processor before all the memory accesses within the "critical" section. As a consequence, it may be possible to have a writer executing a critical section at the same time as readers or another writer. In other words, many of the assumptions (e.g., a variable cannot be modified after a check) in the critical sections are not safe anymore. The read-write locks are used in hypercalls (such as grant-table ones), so a malicious guest could exploit the race. For instance, there is a small window where Xen can leak memory if XENMAPSPACE_grant_table is used concurrently. A malicious guest may be able to leak memory, or cause a hypervisor crash resulting in a Denial of Service (DoS). Information leak and privilege escalation cannot be excluded.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianxen< xen 4.11.4-1 (bookworm)xen 4.11.4-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
xenxen<= 4.13.0
xenxen
xenxen>= 0 < 4.11.4-14.11.4-1
xenxen>= 0 < 4.11.4-14.11.4-1
xenxen>= 0 < 4.11.4-14.11.4-1
xenxen>= 0 < 4.11.4-14.11.4-1
xenxen>= 0 < 4.11.3+24-g14b62ab3e5-1ubuntu2.34.11.3+24-g14b62ab3e5-1ubuntu2.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.