CVE-2020-27672: Use After Free
Published Oct 22, 2020
·Updated
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
Affected Software
6 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.1+2-gb773c48e36-14.17.2+55-g0b56bed864-1
XEN Xen>=3.2.0<=4.14.0
Fedoraproject Fedora=31
openSUSE Leap=15.1
openSUSE Leap=15.2
Debian Debian Linux=10.0
Remediation
Patch Available
Patch Available
Event History
Oct 22, 2020
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-27672.
2
What is the severity of CVE-2020-27672?
The severity of CVE-2020-27672 is high.
3
What software is affected by CVE-2020-27672?
The affected software includes Xen, Debian Linux, Fedoraproject Fedora, and openSUSE Leap.
4
How can x86 guest OS users exploit CVE-2020-27672?
x86 guest OS users can exploit CVE-2020-27672 by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
5
Are there any remedies available for CVE-2020-27672?
Yes, there are remedies available for CVE-2020-27672. Please refer to the advisory links provided for more information.