CVE-2020-29567Allocation of Resources Without Limits or Throttling in XEN

Severity
6.2MEDIUMNVD
EPSS
0.1%
top 82.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 24

Description

An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated and de-allocated on the relevant CPUs. De-allocation has to happen when certain constraints are met. If these conditions are not met when first checked, the checking CPU may send an interrupt to itself, in the expectation that this IRQ will be delivered only after the condition preventing the cleanup has cleared. For two specific IRQ vectors, this exp

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.5 | Impact: 3.6

Affected Packages3 packages

debiandebian/xen< xen 4.14.0+88-g1d1d1f5391-1 (bookworm)
Debianxen/xen< 4.14.0+88-g1d1d1f5391-1+3
NVDxen/xen4.14.0

Also affects: Fedora 33

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x993-24wq-x7c4: An issue was discovered in Xen 42022-05-24
OSV
CVE-2020-29567: An issue was discovered in Xen 42020-12-15

📋Vendor Advisories

1
Debian
CVE-2020-29567: xen - An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribu...2020