CVE-2020-27674
published 2020-10-22CVE-2020-27674: An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because…
PriorityP426medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.36%
28.0th percentile
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.14.0+80-gd101b417b7-1 (bookworm) | xen 4.14.0+80-gd101b417b7-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | <= 4.14.0 | — |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
| xen | xen | >= 0 < 4.14.0+80-gd101b417b7-1 | 4.14.0+80-gd101b417b7-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
vendor_redhat·2020-10-20·CVSS 5.3
CVE-2020-27674 [MEDIUM] CWE-772 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
A flaw was found in the Xen hypercalls with INVLPG-like behavior used by x86 PV guests to invalidate TLB entries. This flaw allows a malicious unprivileged guest user to escalate their privileges to the kernel level within the guest.
Statement: This flaw has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in the Extended Life Phase of the support and ma
Debian
CVE-2020-27674: xen - An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to ...
vendor_debian·2020·CVSS 5.3
CVE-2020-27674 [MEDIUM] CVE-2020-27674: xen - An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to ...
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Scope: local
bookworm: resolved (fixed in 4.14.0+80-gd101b417b7-1)
bullseye: resolved (fixed in 4.14.0+80-gd101b417b7-1)
forky: resolved (fixed in 4.14.0+80-gd101b417b7-1)
sid: resolved (fixed in 4.14.0+80-gd101b417b7-1)
trixie: resolved (fixed in 4.14.0+80-gd101b417b7-1)
GHSA
GHSA-qwpw-7q7c-x5jq: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2020-27674 [HIGH] CWE-119 GHSA-qwpw-7q7c-x5jq: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
OSV
CVE-2020-27674: An issue was discovered in Xen through 4
osv·2020-10-22·CVSS 5.3
CVE-2020-27674 [MEDIUM] CVE-2020-27674: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
bugzilla·2020-10-23·CVSS 5.3
CVE-2020-27674 [MEDIUM] CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
An issue was discovered in all versions of Xen allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1891092]
---
Acknowledgments:
Name: the Xen project
---
External References:
https://xenbits.xen.org/xsa/advisory-286.html
---
Upstream fix:
https://xenbits.xen.org/xsa/xsa286-unstable/0001-x86-pv-Drop-FLUSH_TLB_GLOBAL-in-do_mmu_update-for-XP.patch
https://xenbits.xen.org/xsa/xsa286-unstable/0002-x86-pv-Flush-TLB-in-response-to-paging-structure-cha.patch
---
This bug is now
Bugzilla
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286) [fedora-all]
bugzilla·2020-10-23·CVSS 5.3
CVE-2020-27674 [MEDIUM] CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286) [fedora-all]
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
http://www.openwall.com/lists/oss-security/2021/01/19/5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZAM3LYJ5TZLSSNL3KXFILM46QKVTOUA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3U4LNKKXU4UP4Z5XP6TMIWSML3QODPE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XIK57QJOVOPWH6RFRNMGOBCROBCKMDG2/https://security.gentoo.org/glsa/202011-06https://www.debian.org/security/2020/dsa-4804https://xenbits.xen.org/xsa/advisory-286.htmlhttp://www.openwall.com/lists/oss-security/2021/01/19/5https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZAM3LYJ5TZLSSNL3KXFILM46QKVTOUA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3U4LNKKXU4UP4Z5XP6TMIWSML3QODPE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XIK57QJOVOPWH6RFRNMGOBCROBCKMDG2/https://security.gentoo.org/glsa/202011-06https://www.debian.org/security/2020/dsa-4804https://xenbits.xen.org/xsa/advisory-286.html
2020-10-22
Published