CVE-2020-27670: High severity xen xapi vulnerability
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-table entry can be half-updated.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Xen?
The vulnerability ID for this issue in Xen is CVE-2020-27670.
What is the severity of CVE-2020-27670?
The severity of CVE-2020-27670 is high with a CVSS score of 7.8.
How can x86 guest OS users exploit CVE-2020-27670?
x86 guest OS users can exploit CVE-2020-27670 to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges.
Which versions of Xen are affected by CVE-2020-27670?
Xen versions through 4.14.x are affected by CVE-2020-27670.
Where can I find more information about CVE-2020-27670?
You can find more information about CVE-2020-27670 at the following references: [Xen Advisory 347](https://xenbits.xen.org/xsa/advisory-347.html), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2020-27670), [openSUSE Security Announce](http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00075.html).