CVE-2020-11740Improper Removal of Sensitive Information Before Storage or Transfer in XEN

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 74.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateSep 19

Description

An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Debianxen/xen< 4.11.4-1+3
Ubuntuxen/xen< 4.11.3+24-g14b62ab3e5-1ubuntu2.3
NVDxen/xen3.2.04.13.0+1
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, Fedora 30, 31, 32

Patches

🔴Vulnerability Details

4
OSV
xen vulnerabilities2022-09-19
GHSA
GHSA-cjpx-2x82-p6v9: An issue was discovered in xenoprof in Xen through 42022-05-24
CVEList
CVE-2020-11740: An issue was discovered in xenoprof in Xen through 42020-04-14
OSV
CVE-2020-11740: An issue was discovered in xenoprof in Xen through 42020-04-14

📋Vendor Advisories

3
Ubuntu
Xen vulnerabilities2022-09-19
Red Hat
xen: xenoprof issue allows guest OS users without active profiling to obtain sensitive information about other guests (XSA-313)2020-04-14
Debian
CVE-2020-11740: xen - An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS use...2020

💬Community

2
Bugzilla
CVE-2020-11740 xen: xenoprof issue allows guest OS users without active profiling to obtain sensitive information about other guests (XSA-313) [fedora-all]2020-04-14
Bugzilla
CVE-2020-11740 xen: xenoprof issue allows guest OS users without active profiling to obtain sensitive information about other guests (XSA-313)2020-04-14
CVE-2020-11740 — XEN vulnerability | cvebase