#VU31970 Incorrect default permissions in Xen - CVE-2020-15852
Published: July 28, 2020
Xen
Xen Project
Description
The vulnerability allows a local user to escalate privileges on the system.
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used
in Xen through 4.13.x for x86 PV guests. An attacker may be granted the
I/O port permissions of an unrelated task. This occurs because
tss_invalidate_io_bitmap mishandling causes a loss of synchronization
between the I/O bitmaps of TSS and Xen. A remote user with access to the guest system can gain elevated privileges.