#VU49942 Buffer overflow in Xen - CVE-2020-27674

 

#VU49942 Buffer overflow in Xen - CVE-2020-27674

Published: October 22, 2020 / Updated: January 24, 2021


Vulnerability identifier: #VU49942
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-27674
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Xen
Software vendor:
Xen Project

Description

The vulnerability allows a local authenticated user to read and manipulate data.

An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.


Remediation

Install update from vendor's website.

External links