CVE-2020-29040: High severity xen xapi vulnerability
Published Nov 24, 2020
·Updated
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one error. NOTE: this issue is caused by an incorrect fix for CVE-2020-27671.
Affected Software
1 affected component
XEN Xen<=4.14.0
Event History
Nov 24, 2020
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-29040?
CVE-2020-29040 has a high severity as it can lead to denial of service, data leaks, or privilege escalation.
2
How do I fix CVE-2020-29040?
To fix CVE-2020-29040, you should update Xen to a version higher than 4.14.0.
3
What software versions are affected by CVE-2020-29040?
CVE-2020-29040 affects Xen versions up to and including 4.14.0.
4
What type of vulnerability is CVE-2020-29040?
CVE-2020-29040 is an off-by-one error that can cause stack corruption.
5
Can CVE-2020-29040 lead to privilege escalation?
Yes, CVE-2020-29040 can potentially allow users to gain elevated privileges.