CVE-2020-29484: Null Pointer Dereference

Published Dec 15, 2020
·
Updated

An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore message containing the path of the modified Xenstore entry that triggered the watch, and the tag that was specified when registering the watch. Any communication with xenstored is done via Xenstore messages, consisting of a message header and the payload. The payload length is limited to 4096 bytes. Any request to xenstored resulting in a response with a payload longer than 4096 bytes will result in an error. When registering a watch, the payload length limit applies to the combined length of the watched path and the specified tag. Because watches for a specific path are also triggered for all nodes below that path, the payload of a watch event message can be longer than the payload needed to register the watch. A malicious guest that registers a watch using a very large tag (i.e., with a registration operation payload length close to the 4096 byte limit) can cause the generation of watch events with a payload length larger than 4096 bytes, by writing to Xenstore entries below the watched path. This will result in an error condition in xenstored. This error can result in a NULL pointer dereference, leading to a crash of xenstored. A malicious guest administrator can cause xenstored to crash, leading to a denial of service. Following a xenstored crash, domains may continue to run, but management operations will be impossible. Only C xenstored is affected, oxenstored is not affected.

Affected Software

5 affected componentsFixes available
debian/xen
4.11.4+107-gef32c7afa2-14.14.6-14.14.5+94-ge49571868d-14.17.1+2-gb773c48e36-14.17.2+55-g0b56bed864-1
XEN Xen<=4.14.0
Debian Debian Linux=10.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33

Event History

Dec 15, 2020
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2020-29484?

The severity of CVE-2020-29484 is categorized as medium risk due to potential unauthorized information leakage.

2

How do I fix CVE-2020-29484?

To fix CVE-2020-29484, upgrade to the appropriate patched version of Xen, specifically versions 4.14.6 or later.

3

Which software is affected by CVE-2020-29484?

CVE-2020-29484 affects Xen versions prior to 4.14.6 and various Linux distributions like Debian 10 and Fedora 32 and 33.

4

Is CVE-2020-29484 exploitable remotely?

CVE-2020-29484 requires local access to the Xen environment, making remote exploitation unlikely.

5

What type of vulnerability is CVE-2020-29484?

CVE-2020-29484 is categorized as an information disclosure vulnerability within the Xen hypervisor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203