An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a processor is allowed to re-order the memory access with the preceding ones. In other words, the unlock may be seen by another processor before all the memory accesses within the "critical" section. As a consequence, it may be possible to have a writer executing a critical section at the same time as readers or another writer. In other words, many of the assumptions (e.g., a variable cannot be modified after a check) in the critical sections are not safe anymore. The read-write locks are used in hypercalls (such as grant-table ones), so a malicious guest could exploit the race. For instance, there is a small window where Xen can leak memory if XENMAPSPACE_grant_table is used concurrently. A malicious guest may be able to leak memory, or cause a hypervisor crash resulting in a Denial of Service (DoS). Information leak and privilege escalation cannot be excluded.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Jun 16, 2020 | Apr 14, 2020 |
| Debian | — | Upgrade xen | Jul 14, 2020 | Apr 14, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen. | Jun 15, 2020 | Apr 14, 2020 |
| Suse | — | Upgrade xen-doc-htmlUpgrade xen-libsUpgrade xen-develUpgrade xen-tools-xendomains-wait-diskUpgrade xen-tools-domUUpgrade xen-toolsUpgrade xen-libs-32bitUpgrade xen | May 1, 2020 | Apr 14, 2020 |
| Ubuntu | — | Upgrade libxenmisc4.11Upgrade xen-hypervisor-4.11-arm64Upgrade xen-utils-commonUpgrade libxendevicemodel1Upgrade xenstore-utilsUpgrade libxengnttab1Upgrade xen-hypervisor-4.11-amd64Upgrade xen-utils-4.11Upgrade xen-hypervisor-4.11-armhfUpgrade libxenevtchn1 | Sep 20, 2022 | Apr 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub