CVE-2020-27152
published 2020-11-06CVE-2020-27152: An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.57%
43.9th percentile
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.9.6-1 (bookworm) | linux 5.9.6-1 (bookworm) |
| linux | linux_kernel | < 5.9.2 | 5.9.2 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| msrc | cm1_kernel_5.4.91-1_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2021-02-25·CVSS 5.4
CVE-2020-27152 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)
It was di
Ubuntu
Linux kernel regression
vendor_ubuntu·2020-12-13·CVSS 7.8
[HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: USN-4659-1 introduced a regression in the Linux kernel.
USN-4659-1 fixed vulnerabilities in the Linux kernel. Unfortunately,
that update introduced a regression in the software raid10 driver
when used with fstrim that could lead to data corruption. This update
fixes the problem.
Original advisory details:
It was discovered that a race condition existed in the binder IPC
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-0423)
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allo
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-12-02·CVSS 7.8
CVE-2020-28915 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a race condition existed in the binder IPC
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-0423)
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
It was discovered that a rac
Microsoft
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge trigge
vendor_msrc·2020-11-10·CVSS 5.5
CVE-2020-27152 [MEDIUM] CWE-835 An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge trigge
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering aka CID-77377064c3a9.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is iden
Red Hat
Kernel: KVM: host stack overflow due to lazy update IOAPIC
vendor_redhat·2020-08-02·CVSS 5.5
CVE-2020-27152 [MEDIUM] CWE-835 Kernel: KVM: host stack overflow due to lazy update IOAPIC
Kernel: KVM: host stack overflow due to lazy update IOAPIC
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.
A stack overflow flaw via an infinite loop condition issue was found in the KVM hypervisor of the Linux kernel. This flaw occurs while processing interrupts because the IRQ state is erroneously set. This flaw allows a guest user to crash the host kernel, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
Debian
CVE-2020-27152: linux - An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in th...
vendor_debian·2020·CVSS 5.5
CVE-2020-27152 [MEDIUM] CVE-2020-27152: linux - An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in th...
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.
Scope: local
bookworm: resolved (fixed in 5.9.6-1)
bullseye: resolved (fixed in 5.9.6-1)
forky: resolved (fixed in 5.9.6-1)
sid: resolved (fixed in 5.9.6-1)
trixie: resolved (fixed in 5.9.6-1)
GHSA
GHSA-pfwq-4xp5-gp3h: An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic
ghsa_unreviewed·2022-05-24
CVE-2020-27152 [MEDIUM] CWE-835 GHSA-pfwq-4xp5-gp3h: An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.
OSV
linux-oem-5.6 vulnerabilities
osv·2021-02-25·CVSS 5.4
CVE-2020-10135 [MEDIUM] linux-oem-5.6 vulnerabilities
linux-oem-5.6 vulnerabilities
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)
It was discovered that the block layer implementation in the Linux kernel
did not prope
OSV
CVE-2020-27152: An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic
osv·2020-11-06·CVSS 5.5
CVE-2020-27152 [MEDIUM] CVE-2020-27152: An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.
Kernel
KVM: ioapic: break infinite recursion on lazy EOI
kernel_security·2020-10-24·CVSS 5.5
CVE-2020-27152 [MEDIUM] KVM: ioapic: break infinite recursion on lazy EOI
KVM: ioapic: break infinite recursion on lazy EOI
During shutdown the IOAPIC trigger mode is reset to edge triggered
while the vfio-pci INTx is still registered with a resampler.
This allows us to get into an infinite loop:
ioapic_set_irq
-> ioapic_lazy_update_eoi
-> kvm_ioapic_update_eoi_one
-> kvm_notify_acked_irq
-> kvm_notify_acked_gsi
-> (via irq_acked fn ptr) irqfd_resampler_ack
-> kvm_set_irq
-> (via set fn ptr) kvm_set_ioapic_irq
-> kvm_ioapic_set_irq
-> ioapic_set_irq
Commit 8be8f932e3db ("kvm: ioapic: Restrict lazy EOI update to
edge-triggered interrupts", 2020-05-04) acknowledges that this recursion
loop exists and tries to avoid it at the call to ioapic_lazy_update_eoi,
but at this point the scenario is already set, we have an edge interrupt
with resampler on the same gsi.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27152 Kernel: KVM: host stack overflow due to lazy update IOAPIC
bugzilla·2020-10-16·CVSS 5.5
CVE-2020-27152 [MEDIUM] CVE-2020-27152 Kernel: KVM: host stack overflow due to lazy update IOAPIC
CVE-2020-27152 Kernel: KVM: host stack overflow due to lazy update IOAPIC
A stack overflow via an infinite loop condition issue was found in the KVM hypervisor of the Linux kernel. It could occur while processing interrupts because irq state is erroneously set. A guest user may use this flaw to crash the host kernel resulting in DoS scenario.
Upstream patch:
-> https://git.kernel.org/linus/77377064c3a94911339f13ce113b3abf265e06da
Reference:
-> https://www.openwall.com/lists/oss-security/2020/11/03/1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1888887]
---
Mitigation:
Disabling APICV by setting the kvm_intel.enable_apicv=0 parameter helps to avoid this situation.
---
Patch sent upstream.
---
External References:
https://bugzilla.kernel.org
Bugzilla
CVE-2020-27152 kernel: KVM: host stack overflow due to lazy update IOAPIC [fedora-all]
bugzilla·2020-10-16·CVSS 5.5
CVE-2020-27152 [MEDIUM] CVE-2020-27152 kernel: KVM: host stack overflow due to lazy update IOAPIC [fedora-all]
CVE-2020-27152 kernel: KVM: host stack overflow due to lazy update IOAPIC [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://www.openwall.com/lists/oss-security/2020/11/03/1https://bugzilla.kernel.org/show_bug.cgi?id=208767https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.2https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=77377064c3a94911339f13ce113b3abf265e06dahttp://www.openwall.com/lists/oss-security/2020/11/03/1https://bugzilla.kernel.org/show_bug.cgi?id=208767https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.2https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=77377064c3a94911339f13ce113b3abf265e06da
2020-11-06
Published