CVE-2020-25598
Last modified
CVE-2020-25598 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path in the XENMEM_acquire_resource exits without releasing an RCU reference, which is conceptually similar to forgetting to unlock a spinlock. A buggy or malicious HVM stubdomain can cause an RCU reference to be leaked. This causes subsequent administration operations, (e.g., CPU offline) to livelock, resulting in a host Denial of Service. The buggy codepath has been present since Xen 4.12. Xen 4.14 and later are vulnerable to the DoS. The side effects are believed to be benign on Xen 4.12 and 4.13, but patches are provided nevertheless. The vulnerability can generally only be exploited by x86 HVM VMs, as these are generally the only type of VM that have a Qemu stubdomain. x86 PV and PVH domains, as well as ARM VMs, typically don't use a stubdomain. Only VMs using HVM stubdomains can exploit the vulnerability. VMs using PV stubdomains, or with emulators running in dom0, cannot exploit the vulnerability.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xen | Xen | >= 4.12.0, <= 4.14.0 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Fedoraproject | Fedora | 33 |
| Opensuse | Leap | 15.2 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202011-06Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-334.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202011-06Third Party Advisory
- https://xenbits.xen.org/xsa/advisory-334.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-25598?
How severe is CVE-2020-25598?
How do I fix CVE-2020-25598?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-25592In SaltStack Salt through 3002, salt-netapi improperly valid…9.8
- CVE-2020-25593Acronis True Image through 2021 on macOS allows local privil…6.7
- CVE-2020-25594HashiCorp Vault and Vault Enterprise allowed for enumeration…5.3
- CVE-2020-25595An issue was discovered in Xen through 4.14.x. The PCI passt…7.8
- CVE-2020-25596An issue was discovered in Xen through 4.14.x. x86 PV guest …5.5
- CVE-2020-25597An issue was discovered in Xen through 4.14.x. There is mish…6.5
- CVE-2020-25599An issue was discovered in Xen through 4.14.x. There are evt…7
- CVE-2020-2560Vulnerability in the Siebel UI Framework product of Oracle S…4.7
- CVE-2020-25600An issue was discovered in Xen through 4.14.x. Out of bounds…5.5
- CVE-2020-25601An issue was discovered in Xen through 4.14.x. There is a la…5.5
- CVE-2020-25602An issue was discovered in Xen through 4.14.x. An x86 PV gue…6
- CVE-2020-25603An issue was discovered in Xen through 4.14.x. There are mis…7.8
Are you affected by CVE-2020-25598?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
