CVE-2020-15852
published 2020-07-20CVE-2020-15852: An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.0th percentile
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.7.10-1 (bookworm) | linux 5.7.10-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | 5.5 – 5.7.9 | — |
| xen | xen | <= 4.13.1 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: Linux ioperm bitmap context switching issues
vendor_redhat·2020-07-16·CVSS 7.8
CVE-2020-15852 [HIGH] CWE-270 xen: Linux ioperm bitmap context switching issues
xen: Linux ioperm bitmap context switching issues
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
A flaw was found in the Linux kernel, in the way IOPL and IOPERM system calls were handled during context switches in x86 PV guests. This flaw allows a local guest user to escalate their privileges to the guest. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: The vulnerability can only be exploited in domains which have been gra
Debian
CVE-2020-15852: linux - An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen th...
vendor_debian·2020·CVSS 7.8
CVE-2020-15852 [HIGH] CVE-2020-15852: linux - An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen th...
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
Scope: local
bookworm: resolved (fixed in 5.7.10-1)
bullseye: resolved (fixed in 5.7.10-1)
forky: resolved (fixed in 5.7.10-1)
sid: resolved (fixed in 5.7.10-1)
trixie: resolved (fixed in 5.7.10-1)
GHSA
GHSA-c6v6-mvg4-h5hx: An issue was discovered in the Linux kernel 5
ghsa_unreviewed·2022-05-24
CVE-2020-15852 [MEDIUM] CWE-276 GHSA-c6v6-mvg4-h5hx: An issue was discovered in the Linux kernel 5
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
OSV
CVE-2020-15852: An issue was discovered in the Linux kernel 5
osv·2020-07-20·CVSS 7.8
CVE-2020-15852 [HIGH] CVE-2020-15852: An issue was discovered in the Linux kernel 5
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2020/07/21/2http://xenbits.xen.org/xsa/advisory-329.htmlhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cadfad870154e14f745ec845708bc17d166065f2https://github.com/torvalds/linux/commit/cadfad870154e14f745ec845708bc17d166065f2https://security.netapp.com/advisory/ntap-20200810-0001/http://www.openwall.com/lists/oss-security/2020/07/21/2http://xenbits.xen.org/xsa/advisory-329.htmlhttps://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cadfad870154e14f745ec845708bc17d166065f2https://github.com/torvalds/linux/commit/cadfad870154e14f745ec845708bc17d166065f2https://security.netapp.com/advisory/ntap-20200810-0001/
2020-07-20
Published