Resource management error in Xen - CVE-2020-15566

 

Resource management error in Xen - CVE-2020-15566

Published: July 9, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU29602
CSH Severity: Low
CVSS v4: 8.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H]
CVE-ID: CVE-2020-15566
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling in event-channel port allocation in Xen. An attacker with access to guest operating system can consume more than 1023 event channels and crash the hypervisor.


Affected software

Xen
Debian Linux
Gentoo Linux
Opensuse
Ubuntu
Fedora
xen (Alpine package)
libxengnttab1 (Ubuntu package)
xen-hypervisor-4.11-amd64 (Ubuntu package)
xen-hypervisor-4.11-armhf (Ubuntu package)
libxenmisc4.11 (Ubuntu package)
libxendevicemodel1 (Ubuntu package)
xenstore-utils (Ubuntu package)
xen-utils-4.11 (Ubuntu package)
xen-hypervisor-4.11-arm64 (Ubuntu package)
xen-utils-common (Ubuntu package)
libxenevtchn1 (Ubuntu package)
xen (Debian package)
xen

How to mitigate CVE-2020-15566

Install updates from vendor's website.

xen (Alpine package) - update to 4.12.3-r2
libxengnttab1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-amd64 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-armhf (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxenmisc4.11 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxendevicemodel1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xenstore-utils (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-utils-4.11 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-arm64 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-utils-common (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxenevtchn1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen (Debian package) - update to 4.11.4+24-gddaaccbbab-1~deb10u1
xen - addressed in versions 4.12.3-3.fc31, 4.13.1-4.fc32

External References

Related Security Bulletins