CVE-2020-27671: High severity xen xapi vulnerability
An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27671?
CVE-2020-27671 is an issue discovered in Xen through 4.14.x that allows x86 HVM and PVH guest OS users to cause a denial of service, data corruption, data leak, or possibly gain privileges.
What software is affected by CVE-2020-27671?
Xen versions 4.11.4+107-gef32c7afa2-1, 4.14.6-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, 4.17.2+55-g0b56bed864-1, and earlier versions are affected.
What is the severity of CVE-2020-27671?
The severity of CVE-2020-27671 is rated as high, with a CVSS score of 7.8.
How can CVE-2020-27671 be exploited?
CVE-2020-27671 can be exploited by x86 HVM and PVH guest OS users to cause a denial of service, data corruption, data leak, or potentially gain privileges.
How can I mitigate the impact of CVE-2020-27671?
To mitigate the impact of CVE-2020-27671, it is recommended to update to Xen version 4.14.6-1 or apply the appropriate patch provided by the vendor.