CVE Database
/

CVE-2020-29571

Back to search

CVE-2020-29571

Published: Dec 15, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer side uses appropriately ordered writes, the consumer side isn't protected against re-ordered reads, and may hence end up de-referencing a NULL pointer. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system. Only Arm systems may be vulnerable. Whether a system is vulnerable depends on the specific CPU. x86 systems are not vulnerable.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-4812
vendor-advisory
x_refsource_DEBIAN
FEDORA-2020-64859a826b
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-df772b417b
vendor-advisory
x_refsource_FEDORA
GLSA-202107-30
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now