CVE-2020-25599
published 2020-09-23CVE-2020-25599: An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or…
PriorityP431high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.29%
20.6th percentile
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x86 PV guests may be able to elevate their privilege to that of the host. Host and guest crashes are also possible, leading to a Denial of Service (DoS). Information leaks cannot be ruled out. All Xen versions from 4.5 onwards are vulnerable. Xen versions 4.4 and earlier are not vulnerable.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.14.0+80-gd101b417b7-1 (bookworm) | xen 4.14.0+80-gd101b417b7-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.11.3+24-g14b62ab3e5-1ubuntu2.3 | 4.11.3+24-g14b62ab3e5-1ubuntu2.3 |
| xen | xen | 4.5.0 – 4.14.0 | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Xen vulnerabilities
vendor_ubuntu·2022-09-19·CVSS 5.5
CVE-2020-25599 [MEDIUM] Xen vulnerabilities
Title: Xen vulnerabilities
Summary: Several security issues were fixed in Xen.
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Julien Grall discovered that Xen incorrectly handled memory barriers on
ARM-based systems. An attacker could possibly use this issue to cause a
denial of service, obtain sensitive information or escalate privileges.
(CVE-2020-11739)
Ilja Van Sprundel discovered that Xen incorrectly handled profiling of
guests. An unprivileged attacker could use this issue to obtain
Red Hat
xen: races with evtchn_reset function (XSA-343)
vendor_redhat·2020-09-22·CVSS 7.0
CVE-2020-25599 [HIGH] CWE-440 xen: races with evtchn_reset function (XSA-343)
xen: races with evtchn_reset function (XSA-343)
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x86 PV guests may be able to elevate their privilege to that of the host. Host and guest crashes are also possible, leading to a Denial of Service (DoS). Information leaks cannot be ruled out. All Xen versions from 4.5 onwards are vulnerable. Xen versions 4.4 and earlier are not vulnerable.
A flaw was found in Xen. Uses of EVTCHNOP_reset or XEN_DOMCTL_soft_reset can lead to the violation of vari
Debian
CVE-2020-25599: xen - An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race con...
vendor_debian·2020·CVSS 7.0
CVE-2020-25599 [HIGH] CVE-2020-25599: xen - An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race con...
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x86 PV guests may be able to elevate their privilege to that of the host. Host and guest crashes are also possible, leading to a Denial of Service (DoS). Information leaks cannot be ruled out. All Xen versions from 4.5 onwards are vulnerable. Xen versions 4.4 and earlier are not vulnerable.
Scope: local
bookworm: resolved (fixed in 4.14.0+80-gd101b417b7-1)
bullseye: resolved (fixed in 4.14.0+80-gd101b417b7-1)
forky: resolved (fixed in 4.14.0+80
OSV
xen vulnerabilities
osv·2022-09-19·CVSS 5.5
CVE-2020-0543 [MEDIUM] xen vulnerabilities
xen vulnerabilities
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Julien Grall discovered that Xen incorrectly handled memory barriers on
ARM-based systems. An attacker could possibly use this issue to cause a
denial of service, obtain sensitive information or escalate privileges.
(CVE-2020-11739)
Ilja Van Sprundel discovered that Xen incorrectly handled profiling of
guests. An unprivileged attacker could use this issue to obtain sensitive
information from other guests, cause a denial of s
GHSA
GHSA-565v-439w-r6r9: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2020-25599 [HIGH] CWE-119 GHSA-565v-439w-r6r9: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x86 PV guests may be able to elevate their privilege to that of the host. Host and guest crashes are also possible, leading to a Denial of Service (DoS). Information leaks cannot be ruled out. All Xen versions from 4.5 onwards are vulnerable. Xen versions 4.4 and earlier are not vulnerable.
OSV
CVE-2020-25599: An issue was discovered in Xen through 4
osv·2020-09-23·CVSS 7.0
CVE-2020-25599 [HIGH] CVE-2020-25599: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x86 PV guests may be able to elevate their privilege to that of the host. Host and guest crashes are also possible, leading to a Denial of Service (DoS). Information leaks cannot be ruled out. All Xen versions from 4.5 onwards are vulnerable. Xen versions 4.4 and earlier are not vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25599 xen: races with evtchn_reset function (XSA-343) [fedora-all]
bugzilla·2020-09-22·CVSS 7.0
CVE-2020-25599 [HIGH] CVE-2020-25599 xen: races with evtchn_reset function (XSA-343) [fedora-all]
CVE-2020-25599 xen: races with evtchn_reset function (XSA-343) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2020-25599 xen: races with evtchn_reset function (XSA-343)
bugzilla·2020-09-16·CVSS 7.0
CVE-2020-25599 [HIGH] CVE-2020-25599 xen: races with evtchn_reset function (XSA-343)
CVE-2020-25599 xen: races with evtchn_reset function (XSA-343)
Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks.
Discussion:
Acknowledgments:
Name: the Xen project
---
Statement:
All Xen versions from 4.4 onwards are vulnerable. Red Hat Enterprise Linux 5 is not affected by this flaw, as it shipped an older version of Xen.
---
Mitigation:
There is no known mitigation for this flaw apart from applying the patch.
---
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1881581]
---
This bug is now closed. Further updates for individual products will be reflected on the
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.htmlhttp://www.openwall.com/lists/oss-security/2020/12/16/5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JRXMKEMQRQYWYEPHVBIWUEAVQ3LU4FN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA633Y3G5KX7MKRN4PFEGM3IVTJMBEOM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJZERRBJN6E6STDCHT4JHP4MI6TKBCJE/https://security.gentoo.org/glsa/202011-06https://www.debian.org/security/2020/dsa-4769https://xenbits.xen.org/xsa/advisory-343.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.htmlhttp://www.openwall.com/lists/oss-security/2020/12/16/5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JRXMKEMQRQYWYEPHVBIWUEAVQ3LU4FN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA633Y3G5KX7MKRN4PFEGM3IVTJMBEOM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJZERRBJN6E6STDCHT4JHP4MI6TKBCJE/https://security.gentoo.org/glsa/202011-06https://www.debian.org/security/2020/dsa-4769https://xenbits.xen.org/xsa/advisory-343.html
2020-09-23
Published