First published: Thu Oct 22 2020(Updated: )
An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing of per-page IOMMU TLB flushes is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/xen | 4.11.4+107-gef32c7afa2-1 4.14.6-1 4.14.5+94-ge49571868d-1 4.17.1+2-gb773c48e36-1 4.17.2+55-g0b56bed864-1 | |
Xen Xen | >=4.2.0<=4.14.0 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27671 is an issue discovered in Xen through 4.14.x that allows x86 HVM and PVH guest OS users to cause a denial of service, data corruption, data leak, or possibly gain privileges.
Xen versions 4.11.4+107-gef32c7afa2-1, 4.14.6-1, 4.14.5+94-ge49571868d-1, 4.17.1+2-gb773c48e36-1, 4.17.2+55-g0b56bed864-1, and earlier versions are affected.
The severity of CVE-2020-27671 is rated as high, with a CVSS score of 7.8.
CVE-2020-27671 can be exploited by x86 HVM and PVH guest OS users to cause a denial of service, data corruption, data leak, or potentially gain privileges.
To mitigate the impact of CVE-2020-27671, it is recommended to update to Xen version 4.14.6-1 or apply the appropriate patch provided by the vendor.