CVE-2020-11743
Summary
| CVE | CVE-2020-11743 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-14 13:15:00 UTC |
| Updated | 2023-11-07 03:15:00 UTC |
| Description | An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 for success, and a negative number for errors. Some misplaced brackets cause one error path to return 1 instead of a negative value. The grant table code in Linux treats this condition as success, and proceeds with incorrectly initialised state. A buggy or malicious guest can construct its grant table in such a way that, when a backend domain tries to map a grant, it hits the incorrect error path. This will crash a Linux based dom0 or backend domain. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Fedoraproject |
Fedora |
32 |
All |
All |
All |
| Operating System |
Fedoraproject |
Fedora |
32 |
All |
All |
All |
| Operating System |
Xen |
Xen |
4.13.0 |
rc1 |
All |
All |
| Operating System |
Xen |
Xen |
4.13.0 |
rc2 |
All |
All |
| Operating System |
Xen |
Xen |
4.13.0 |
rc1 |
All |
All |
| Operating System |
Xen |
Xen |
4.13.0 |
rc2 |
All |
All |
| Operating System |
Xen |
Xen |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 30 Update: xen-4.11.4-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: xen-4.13.0-7.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| XSA-316 - Xen Security Advisories |
CONFIRM |
xenbits.xen.org |
Exploit, Vendor Advisory |
| Xen: Multiple vulnerabilities (GLSA 202005-08) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 32 Update: xen-4.13.0-7.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: xen-4.11.4-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| XSA-316 - Xen Security Advisories |
MISC |
xenbits.xen.org |
Exploit, Vendor Advisory |
| [SECURITY] Fedora 31 Update: xen-4.12.2-3.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-4723-1 xen |
DEBIAN |
www.debian.org |
|
| oss-security - Xen Security Advisory 316 v3 (CVE-2020-11743) - Bad error path in
GNTTABOP_map_grant |
MLIST |
www.openwall.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 31 Update: xen-4.12.2-3.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:0599-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198943 Ubuntu Security Notification for Xen Vulnerabilities (USN-5617-1)
- 378872 Citrix XenServer Security Updates (CTX270837)
- 500755 Alpine Linux Security Update for xen
- 500788 Alpine Linux Security Update for xen
- 501174 Alpine Linux Security Update for xen
- 504532 Alpine Linux Security Update for xen