CVE-2020-29487: High severity xen vulnerability

Published Dec 15, 2020
·
Updated

An issue was discovered in Xen XAPI before 2020-12-15. Certain xenstore keys provide feedback from the guest, and are therefore watched by toolstack. Specifically, keys are watched by xenopsd, and data are forwarded via RPC through message-switch to xapi. The watching logic in xenopsd sends one RPC update containing all data, any time any single xenstore key is updated, and therefore has O(N^2) time complexity. Furthermore, message-switch retains recent (currently 128) RPC messages for diagnostic purposes, yielding O(MN) space complexity. The quantity of memory a single guest can monopolise is bounded by xenstored quota, but the quota is fairly large. It is believed to be in excess of 1G per malicious guest. In practice, this manifests as a host denial of service, either through message-switch thrashing against swap, or OOMing entirely, depending on dom0's configuration. (There are no quotas in xenopsd to limit the quantity of keys that result in RPC traffic.) A buggy or malicious guest can cause unreasonable memory usage in dom0, resulting in a host denial of service. All versions of XAPI are vulnerable. Systems that are not using the XAPI toolstack are not vulnerable.

Affected Software

1 affected component
XEN XAPI<2020-12-15

Event History

Dec 15, 2020
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2020-29487?

CVE-2020-29487 has a moderate severity due to its potential impact on security and information disclosure.

2

How do I fix CVE-2020-29487?

To mitigate CVE-2020-29487, upgrade the Xen XAPI to a version later than 2020-12-15.

3

What software is affected by CVE-2020-29487?

CVE-2020-29487 affects Xen XAPI versions prior to 2020-12-15.

4

What type of vulnerability is CVE-2020-29487?

CVE-2020-29487 is primarily an information disclosure vulnerability.

5

Is there a workaround for CVE-2020-29487?

Currently, there are no known workarounds for CVE-2020-29487 other than upgrading to a safe version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203