CVE-2020-27674

MEDIUM

Xen < 4.14.0 - Unauthenticated Out-of-bounds Write via TLB Invalidation Mishandling

Title source: llm
STIX 2.1

Description

An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.

References (7)

Core 7
Core References
Patch, Vendor Advisory x_refsource_misc
https://xenbits.xen.org/xsa/advisory-286.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202011-06
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4804
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/01/19/5

Scores

CVSS v3 5.3
EPSS 0.0007
EPSS Percentile 22.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-787
Status published
Products (5)
debian/debian_linux 10.0
fedoraproject/fedora 31
fedoraproject/fedora 32
fedoraproject/fedora 33
xen/xen < 4.14.0
Published Oct 22, 2020
Tracked Since Feb 18, 2026