Resource management error in Xen - CVE-2020-25602
Published: September 23, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when processing guest requests to the "MISC_ENABLE MSR" register in Xen. A remote privileged PV guest can run a specially crafted program and crash Xen.
Only non-non-Intel x86 systems are affected.
Affected software
Gentoo Linux
Opensuse
Ubuntu
Fedora
xen (Alpine package)
xen (Debian package)
libxenevtchn1 (Ubuntu package)
libxengnttab1 (Ubuntu package)
xen-hypervisor-4.11-amd64 (Ubuntu package)
xen-hypervisor-4.11-armhf (Ubuntu package)
libxenmisc4.11 (Ubuntu package)
libxendevicemodel1 (Ubuntu package)
xenstore-utils (Ubuntu package)
xen-utils-4.11 (Ubuntu package)
xen-hypervisor-4.11-arm64 (Ubuntu package)
xen-utils-common (Ubuntu package)
xen
app-emulation/xen
app-emulation/xen-tools
How to mitigate CVE-2020-25602
xen (Debian package) - update to 4.11.4+37-g3263f257ca-1
libxenevtchn1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxengnttab1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-amd64 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-armhf (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxenmisc4.11 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
libxendevicemodel1 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xenstore-utils (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-utils-4.11 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-hypervisor-4.11-arm64 (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen-utils-common (Ubuntu package) - update to 4.11.3+24-g14b62ab3e5-1ubuntu2.3
xen - addressed in versions 4.12.3-5.fc31, 4.13.1-6.fc32, 4.14.0-5.fc33
app-emulation/xen - update to 4.13.2
app-emulation/xen-tools - update to 4.13.2