CVE-2020-29481: High severity xen xapi vulnerability
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/<domid> are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29481?
CVE-2020-29481 has a moderate severity level due to the improper handling of access rights in Xenstore.
How do I fix CVE-2020-29481?
To fix CVE-2020-29481, upgrade to a version of Xen that is not affected, such as those released after 4.14.0.
Which versions of Xen are affected by CVE-2020-29481?
CVE-2020-29481 affects Xen versions up to and including 4.14.0.
What impact does CVE-2020-29481 have on system security?
The impact of CVE-2020-29481 allows a new domain to inherit access rights improperly, potentially leading to privilege escalation.
Is CVE-2020-29481 a local or remote vulnerability?
CVE-2020-29481 is primarily a local vulnerability as it involves access rights within the hypervisor environment.