cbcvebase.
CVE-2020-29569
published 2020-12-15

CVE-2020-29569: An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread…

PriorityP343high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.39%
31.5th percentile
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to run if the frontend quickly toggles between the states connect and disconnect. As a consequence, the block backend may re-use a pointer after it was freed. A misbehaving guest can trigger a dom0 crash by continuously connecting / disconnecting a block frontend. Privilege escalation and information leaks cannot be ruled out. This only affects systems with a Linux blkback.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.9.15-1 (bookworm)linux 5.9.15-1 (bookworm)
linuxlinux_kernel>= 0 < 5.9.15-15.9.15-1
linuxlinux_kernel>= 0 < 5.9.15-15.9.15-1
linuxlinux_kernel>= 0 < 5.9.15-15.9.15-1
linuxlinux_kernel>= 0 < 5.9.15-15.9.15-1
linuxlinux_kernel>= 0 < 4.4.0-204.2364.4.0-204.236
linuxlinux_kernel>= 0 < 4.15.0-136.1404.15.0-136.140
linuxlinux_kernel>= 0 < 5.4.0-66.745.4.0-66.74
linuxlinux_kernel>= 4.1.44 < 4.24.2
linuxlinux_kernel>= 4.11.9 < 4.124.12
linuxlinux_kernel>= 4.12 < 4.14.2134.14.213
linuxlinux_kernel>= 4.15 < 4.19.1644.19.164
linuxlinux_kernel>= 4.20 < 5.4.865.4.86
linuxlinux_kernel>= 4.4.80 < 4.4.2544.4.254
linuxlinux_kernel>= 4.9.36 < 4.9.2494.9.249
linuxlinux_kernel>= 5.5 < 5.10.45.10.4
msrccm1_kernel_5.4.91-1_on_cbl_mariner_1.0
paloaltopan-os
xenxen<= 4.14.1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.