Severity
8.8HIGHNVD
NVD7.8OSV5.5
EPSS
0.1%
top 77.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 7
Latest updateSep 19

Description

An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require flushing of both TLBs. Furthermore, IOMMUs may be non-coherent, and hence prior to flushing IOMMU TLBs, a CPU cache also needs writing back to memory after changes were made. Such writing back of cached data was missing in

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages4 packages

NVDxen/xen3.2.04.12.0+1
Debianxen/xen< 4.11.4+24-gddaaccbbab-1+7
Ubuntuxen/xen< 4.11.3+24-g14b62ab3e5-1ubuntu2.3
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 10.0, Fedora 31, 32

Patches

🔴Vulnerability Details

7
OSV
xen vulnerabilities2022-09-19
GHSA
GHSA-f444-f4gw-jhg6: An issue was discovered in Xen through 42022-05-24
GHSA
GHSA-xcjp-mj7m-5f57: An issue was discovered in Xen through 42022-05-24
CVEList
CVE-2021-27379: An issue was discovered in Xen through 42021-02-18
OSV
CVE-2021-27379: An issue was discovered in Xen through 42021-02-18

📋Vendor Advisories

4
Ubuntu
Xen vulnerabilities2022-09-19
Debian
CVE-2021-27379: xen - An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS u...2021
Red Hat
xen: insufficient cache write-back under VT-d leads to DoS (XSA-321)2020-07-07
Debian
CVE-2020-15565: xen - An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS u...2020

💬Community

2
Bugzilla
CVE-2020-15565 xen: insufficient cache write-back under VT-d leads to DoS (XSA-321) [fedora-all]2020-07-07
Bugzilla
CVE-2020-15565 xen: insufficient cache write-back under VT-d leads to DoS (XSA-321)2020-06-26
CVE-2020-15565 — Uncontrolled Resource Consumption | cvebase