CVE-2020-29481
published 2020-12-15CVE-2020-29481: An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed…
PriorityP341high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.35%
26.9th percentile
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/ are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xen | < xen 4.14.0+88-g1d1d1f5391-1 (bookworm) | xen 4.14.0+88-g1d1d1f5391-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| xen | xen | <= 4.14.0 | — |
| xen | xen | >= 0 < 4.14.0+88-g1d1d1f5391-1 | 4.14.0+88-g1d1d1f5391-1 |
| xen | xen | >= 0 < 4.14.0+88-g1d1d1f5391-1 | 4.14.0+88-g1d1d1f5391-1 |
| xen | xen | >= 0 < 4.14.0+88-g1d1d1f5391-1 | 4.14.0+88-g1d1d1f5391-1 |
| xen | xen | >= 0 < 4.14.0+88-g1d1d1f5391-1 | 4.14.0+88-g1d1d1f5391-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vcqm-hqq4-5mxm: An issue was discovered in Xen through 4
ghsa_unreviewed·2022-05-24
CVE-2020-29481 [HIGH] CWE-668 GHSA-vcqm-hqq4-5mxm: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/ are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
OSV
CVE-2020-29481: An issue was discovered in Xen through 4
osv·2020-12-15·CVSS 8.8
CVE-2020-29481 [HIGH] CVE-2020-29481: An issue was discovered in Xen through 4
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/ are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
Debian
CVE-2020-29481: xen - An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes a...
vendor_debian·2020·CVSS 8.8
CVE-2020-29481 [HIGH] CVE-2020-29481: xen - An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes a...
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/ are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
Scope: local
bookworm: resolved (fixed in 4.14.0+88-g1d1d1f5391-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2020/12/16/3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2C6M6S3CIMEBACH6O7V4H2VDANMO6TVA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OBLV6L6Q24PPQ2CRFXDX4Q76KU776GKI/https://www.debian.org/security/2020/dsa-4812https://xenbits.xenproject.org/xsa/advisory-322.htmlhttp://www.openwall.com/lists/oss-security/2020/12/16/3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2C6M6S3CIMEBACH6O7V4H2VDANMO6TVA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OBLV6L6Q24PPQ2CRFXDX4Q76KU776GKI/https://www.debian.org/security/2020/dsa-4812https://xenbits.xenproject.org/xsa/advisory-322.html
2020-12-15
Published