VULNERABILITY

Ubuntu: (Multiple Advisories) (CVE-2020-15563): Xen vulnerabilities

Try Surface Command Get a continuous 360° view of your attack surface
Back to Search

Ubuntu: (Multiple Advisories) (CVE-2020-15563): Xen vulnerabilities

Severity
5
CVSS
(AV:L/AC:M/Au:N/C:N/I:N/A:C)
Published
07/07/2020
Created
09/21/2022
Added
09/20/2022
Modified
10/23/2024

Description

An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A malicious or buggy HVM guest may cause the hypervisor to crash, resulting in Denial of Service (DoS) affecting the entire host. Xen versions from 4.8 onwards are affected. Xen versions 4.7 and earlier are not affected. Only x86 systems are affected. Arm systems are not affected. Only x86 HVM guests using shadow paging can leverage the vulnerability. In addition, there needs to be an entity actively monitoring a guest's video frame buffer (typically for display purposes) in order for such a guest to be able to leverage the vulnerability. x86 PV guests, as well as x86 HVM guests using hardware assisted paging (HAP), cannot leverage the vulnerability.

Solution(s)

  • ubuntu-upgrade-libxendevicemodel1
  • ubuntu-upgrade-libxenevtchn1
  • ubuntu-upgrade-libxengnttab1
  • ubuntu-upgrade-libxenmisc4-11
  • ubuntu-upgrade-xen-hypervisor-4-11-amd64
  • ubuntu-upgrade-xen-hypervisor-4-11-arm64
  • ubuntu-upgrade-xen-hypervisor-4-11-armhf
  • ubuntu-upgrade-xen-utils-4-11
  • ubuntu-upgrade-xen-utils-common
  • ubuntu-upgrade-xenstore-utils

insightVM

Advanced vulnerability management analytics and reporting.
Key Features
  • Lightweight Endpoint Agent
  • Live Dashboards
  • Real Risk Prioritization
  • IT-Integrated Remediation Projects
  • Cloud, Virtual, and Container Assessment
  • Integrated Threat Feeds
  • Easy-to-Use RESTful API
  • Automation-Assisted Patching
  • Automated Containment
Free InsightVM Trial View All Features

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;