CVE-2020-27673Uncontrolled Resource Consumption in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 89.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 24

Description

An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel2.6.124.4.244+6
Debianlinux/linux_kernel< 5.9.6-1+3
NVDxen/xen4.14.0
NVDopensuse/leap15.1, 15.2+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hj67-hpcv-3wx5: An issue was discovered in the Linux kernel through 52022-05-24
OSV
CVE-2020-27673: An issue was discovered in the Linux kernel through 52020-10-22
CVEList
CVE-2020-27673: An issue was discovered in the Linux kernel through 52020-10-22

📋Vendor Advisories

3
Ubuntu
Linux kernel vulnerabilities2021-02-25
Red Hat
kernel: xen: guest OS users can cause a DoS via a high rate of events to dom0 (XSA-332)2020-10-20
Debian
CVE-2020-27673: linux - An issue was discovered in the Linux kernel through 5.9.1, as used with Xen thro...2020

💬Community

2
Bugzilla
CVE-2020-27673 kernel: xen: guest OS users can cause a DoS via a high rate of events to dom0 (XSA-332)2020-10-23
Bugzilla
CVE-2020-27673 kernel: xen: guest OS users can cause a DoS via a high rate of events to dom0 (XSA-332) [fedora-all]2020-10-23
CVE-2020-27673 — Uncontrolled Resource Consumption | cvebase