4.9
CVSSv2

CVE-2020-29568

Published: 15/12/2020 Updated: 26/04/2022
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

An issue exists in Xen up to and including 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks CVE-2020-27815 A flaw was reported in the JFS filesystem code allowing a local attacker with the ability to set extended attributes to cause a denial of service CVE-2020-27825 Adam pi3 Z ...
In the Linux kernel 5021, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutexc This is related to mutex_can_spin_on_owner in kernel/locking/mutexc, __btrfs_qgroup_free_meta in fs/btrfs/qgroupc, and btrfs_insert_delayed_ ...
A flaw was found in the JFS filesystem code This flaw allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability (CVE-2020-27815) A flaw was found in the Linu ...
In the Linux kernel 5021, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutexc This is related to mutex_can_spin_on_owner in kernel/locking/mutexc, __btrfs_qgroup_free_meta in fs/btrfs/qgroupc, and btrfs_insert_delayed_ ...
Description of Problem Several security issues have been identified that, collectively, may allow privileged code running in a guest VM to compromise the host or cause a denial of service These vulnerabilities have the following identifiers:  CVE ID Description Vulnerability Type Pre-conditions CVE-2020-29479 An attacker with the ability to ...