CVE-2020-29570
Summary
| CVE | CVE-2020-29570 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-15 17:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-4812-1 xen |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 33 Update: xen-4.14.0-14.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| XSA-358 - Xen Security Advisories |
MISC |
xenbits.xenproject.org |
Patch, Vendor Advisory |
| oss-security - Xen Security Advisory 358 v5 (CVE-2020-29570) - FIFO event
channels control block related ordering |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| Xen: Multiple vulnerabilities (GLSA 202107-30) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 32 Update: xen-4.13.2-5.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 32 Update: xen-4.13.2-5.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: xen-4.14.0-14.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377779 Citrix XenServer Security Updates (CTX286756)
- 500796 Alpine Linux Security Update for xen
- 501515 Alpine Linux Security Update for xen
- 504539 Alpine Linux Security Update for xen
- 710038 Gentoo Linux Xen Multiple vulnerabilities (GLSA 202107-30)
- 750465 OpenSUSE Security Update for xen (openSUSE-SU-2020:2331-1)
- 750474 OpenSUSE Security Update for xen (openSUSE-SU-2020:2313-1)