xen: missing alignment check in VCPUOP_register_vcpu_info leads to DoS (XSA-327)
Published Jul 7, 2020
6.5
MEDIUMCVSS 3.1
EPSS 0.40%
Description
An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by a guest to register a shared region with the hypervisor. The region will be mapped into Xen address space so it can be directly accessed. On Arm, the region is accessed with instructions that require a specific alignment. Unfortunately, there is no check that the address provided by the guest will be correctly aligned. As a result, a malicious guest could cause a hypervisor crash by passing a misaligned address. A malicious guest administrator may cause a hypervisor crash, resulting in a Denial of Service (DoS). All Xen versions are vulnerable. Only Arm systems are vulnerable. x86 systems are not affected.
Affected products
No data.
Configuration 2
- 10.0
Configuration 3
- 31
- 32
No data.
Red Hat Enterprise Linux 5
kernel-xen
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-xen | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Only ARM systems are vulnerable, x86 systems are not affected by this flaw.
References (12)
- http://www.openwall.com/lists/oss-security/2020/07/07/5 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://xenbits.xen.org/xsa/advisory-327.html x_refsource_MISCPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-15564 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1851470 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7551 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MXESCOVI7AVRNC7HEAMFM7PMEO6D3AUH/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB3QJJZV23Z2IDYEMIHELWYSQBUEW6JP/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-15564
- https://security.gentoo.org/glsa/202007-02 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-15564
- https://www.debian.org/security/2020/dsa-4723 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://xenbits.xen.org/xsa/advisory-327.html
Change history (0)
No recorded changes yet.