An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer side uses appropriately ordered writes, the consumer side isn't protected against re-ordered reads, and may hence end up de-referencing a NULL pointer. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system. Only Arm systems may be vulnerable. Whether a system is vulnerable depends on the specific CPU. x86 systems are not vulnerable.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xen | Mar 26, 2024 | Dec 15, 2020 |
| Debian | — | Upgrade xen | Dec 17, 2020 | Dec 15, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/xen. | Jul 13, 2021 | Dec 15, 2020 |
| Suse | — | Upgrade xen-kmp-defaultUpgrade xen-toolsUpgrade xen-libsUpgrade xen-kmp-paeUpgrade xen-tools-xendomains-wait-diskUpgrade xen-doc-htmlUpgrade xenUpgrade xen-develUpgrade xen-libs-32bitUpgrade xen-tools-domU | Dec 17, 2020 | Dec 15, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub