CVE-2020-27674
Summary
| CVE | CVE-2020-27674 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-22 21:15:00 UTC |
| Updated | 2023-11-07 03:20:00 UTC |
| Description | An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 32 Update: xen-4.13.2-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Xen: Multiple vulnerabilities (GLSA 202011-06) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 31 Update: xen-4.12.3-8.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: xen-4.14.0-9.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-4804-1 xen |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 31 Update: xen-4.12.3-8.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: xen-4.14.0-9.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - Xen Security Advisory 286 v6 (CVE-2020-27674) - x86 PV guest
INVLPG-like flushes may leave stale TLB entries |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 32 Update: xen-4.13.2-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| XSA-286 - Xen Security Advisories |
MISC |
xenbits.xen.org |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378881 Citrix XenServer Security Updates (CTX284874)
- 500793 Alpine Linux Security Update for xen
- 501513 Alpine Linux Security Update for xen
- 504537 Alpine Linux Security Update for xen
- 750502 OpenSUSE Security Update for xen (openSUSE-SU-2020:2192-1)
- 750519 OpenSUSE Security Update for xen (openSUSE-SU-2020:2162-1)