CVE-2020-27152: Medium severity linux kernel vulnerability

Published Aug 2, 2020
·
Updated

A stack overflow flaw via an infinite loop condition issue was found in the KVM hypervisor of the Linux kernel. This flaw occurs while processing interrupts because the IRQ state is erroneously set. This flaw allows a guest user to crash the host kernel, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

Other sources

A stack overflow via an infinite loop condition issue was found in the KVM hypervisor of the Linux kernel. It could occur while processing interrupts because irq state is erroneously set. A guest user may use this flaw to crash the host kernel resulting in DoS scenario.

Upstream patch: --------------- -> https://git.kernel.org/linus/77377064c3a94911339f13ce113b3abf265e06da

Reference: ---------- -> https://www.openwall.com/lists/oss-security/2020/11/03/1

Red Hat

An issue was discovered in ioapiclazyupdateeoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.

Affected Software

5 affected componentsFixes available
redhat/kernel-rt<0:4.18.0-240.22.1.rt7.77.el8_3
0:4.18.0-240.22.1.rt7.77.el8_3
redhat/kernel<0:4.18.0-240.22.1.el8_3
0:4.18.0-240.22.1.el8_3
redhat/Linux<5.10
5.10
Linux Linux kernel<5.9.2
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Remediation

Information

Disabling APICV by setting the kvm_intel.enable_apicv=0 parameter helps to avoid this situation.

Event History

Aug 2, 2020
CVE Published
12:00 AM
Nov 6, 2020
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:47 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:26 AM
RemedyDescriptionSeverityAffected Software
Apr 12, 2025
Data Sourced
via Debian·04:19 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2020-27152?

CVE-2020-27152 is classified with a high severity rating due to its potential to cause denial of service.

2

How can I fix CVE-2020-27152?

To fix CVE-2020-27152, update your Linux kernel to version 0:4.18.0-240.22.1.rt7.77.el8_3 or later, or to 5.10.223-1 or later, as recommended.

3

Which systems are affected by CVE-2020-27152?

CVE-2020-27152 affects various Linux kernel versions, specifically those prior to 5.10.

4

What impact does CVE-2020-27152 have on system performance?

CVE-2020-27152 can lead to a stack overflow, resulting in the crashing of the host kernel and overall system instability.

5

Is CVE-2020-27152 remote exploit opportunity?

Yes, CVE-2020-27152 can be exploited by a guest user to crash the host, leading to a denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203