CVE-2020-27675Race Condition in Linux

Severity
4.7MEDIUMNVD
OSV8.2OSV5.5OSV4.1
EPSS
0.1%
top 80.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 24

Description

An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as demonstrated by a dom0 crash via events for an in-reconfiguration paravirtualized device, aka CID-073d0552ead5.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages7 packages

Debianlinux/linux_kernel< 5.9.6-1+3
Ubuntulinux/linux_kernel< 4.4.0-198.230+2
debiandebian/linux< linux 5.9.6-1 (bookworm)

Also affects: Debian Linux 9.0, Fedora 31, 32, 33

Patches

🔴Vulnerability Details

6
GHSA
GHSA-3vrm-64pq-5964: An issue was discovered in the Linux kernel through 52022-05-24
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities2021-02-25
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2021-01-06
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabi2021-01-06
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2, linux-snapdragon vulnerabilities2021-01-06

📋Vendor Advisories

7
Ubuntu
Linux kernel vulnerabilities2021-02-25
Ubuntu
Linux kernel vulnerabilities2021-01-06
Ubuntu
Linux kernel vulnerabilities2021-01-06
Ubuntu
Linux kernel vulnerabilities2021-01-06
Red Hat
kernel: xen: race condition in event-channel removal during the event-handling loop (XSA-331)2020-10-20

💬Community

2
Bugzilla
CVE-2020-27675 kernel: xen: race condition in event-channel removal during the event-handling loop (XSA-331)2020-10-23
Bugzilla
CVE-2020-27675 kernel: xen: race condition in event-channel removal during the event-handling loop (XSA-331) [fedora-all]2020-10-23