Missing Authorization in Xen - CVE-2020-11741
Published: July 28, 2020
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
An issue was discovered in xenoprof in Xen through 4.13.x, allowing
guest OS users (with active profiling) to obtain sensitive information
about other guests, cause a denial of service, or possibly gain
privileges. For guests for which "active" profiling
was enabled by the administrator, the xenoprof code uses the standard
Xen shared ring structure. Unfortunately, this code did not treat the
guest as a potential adversary: it trusts the guest not to modify buffer
size information or modify head / tail pointers in unexpected ways. A remote user can perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Debian Linux
Opensuse
Ubuntu
Fedora
xen (Alpine package)
xen
libxengnttab1 (Ubuntu package)
xen-hypervisor-4.11-amd64 (Ubuntu package)
xen-hypervisor-4.11-armhf (Ubuntu package)
libxenmisc4.11 (Ubuntu package)
libxendevicemodel1 (Ubuntu package)
xenstore-utils (Ubuntu package)
xen-utils-4.11 (Ubuntu package)
xen-hypervisor-4.11-arm64 (Ubuntu package)
xen-utils-common (Ubuntu package)
libxenevtchn1 (Ubuntu package)
xen (Debian package)
How to mitigate CVE-2020-11741
xen - addressed in versions 4.11.3-4.fc30, 4.11.4-1.fc30, 4.12.2-3.fc31, 4.13.0-7.fc32
libxengnttab1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-amd64 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-armhf (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxenmisc4.11 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxendevicemodel1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xenstore-utils (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-utils-4.11 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-arm64 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-utils-common (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxenevtchn1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen (Debian package) - update to 4.11.4+24-gddaaccbbab-1~deb10u1
External References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00006.html
- http://www.openwall.com/lists/oss-security/2020/04/14/1
- http://xenbits.xen.org/xsa/advisory-313.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5M2XRNCHOGGTJQBZQJ7DCV6ZNAKN3LE2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NVTP4OYHCTRU3ONFJOFJQVNDFB25KLLG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YMAW7D2MP6RE4BFI5BZWOBBWGY3VSOFN/
- https://security.gentoo.org/glsa/202005-08
- https://www.debian.org/security/2020/dsa-4723
- https://xenbits.xen.org/xsa/advisory-313.html