CVE-2020-15852: High severity linux kernel vulnerability
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tssinvalidateiobitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-15852?
CVE-2020-15852 is a vulnerability in the Linux kernel, specifically in versions 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests.
How does CVE-2020-15852 work?
CVE-2020-15852 allows an attacker to be granted the I/O port permissions of an unrelated task due to mishandling in tss_invalidate_io_bitmap, leading to a loss of synchronization between the I/O bitmaps.
What is the severity of CVE-2020-15852?
The severity of CVE-2020-15852 is high, with a severity value of 7.8.
Which software is affected by CVE-2020-15852?
The Linux kernel versions 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests, as well as Netapp Cloud Backup, Netapp Steelstore Cloud Integrated Storage, and Netapp Solidfire Baseboard Management Controller are affected by CVE-2020-15852.
How do I fix CVE-2020-15852?
To fix CVE-2020-15852, users should apply the necessary security patches provided by the Linux kernel and Xen, as well as follow any remediation steps recommended by Netapp for their affected products.