xen: x86 pv guest kernel DoS via SYSENTER (XSA-339)
Published Sep 23, 2020
5.5
MEDIUMCVSS 3.1
EPSS 0.51%
Description
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. This causes the guest kernel to observe a kernel-privilege #GP fault (typically fatal) rather than a user-privilege #GP fault (usually converted into SIGSEGV/etc.). Malicious or buggy userspace can crash the guest kernel, resulting in a VM Denial of Service. All versions of Xen from 3.2 onwards are vulnerable. Only x86 systems are vulnerable. ARM platforms are not vulnerable. Only x86 systems that support the SYSENTER instruction in 64bit mode are vulnerable. This is believed to be Intel, Centaur, and Shanghai CPUs. AMD and Hygon CPUs are not believed to be vulnerable. Only x86 PV guests can exploit the vulnerability. x86 PVH / HVM guests cannot exploit the vulnerability.
Affected products
No data.
Configuration 2
- 31
- 32
- 33
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 5
kernel-xen
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-xen | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
All Xen versions from 3.2 onward are vulnerable. Red Hat Enterprise Linux 5 is not affected by this flaw, as it shipped in an older version of Xen.
Red Hat mitigation
Running only x86 PVH/HVM guests avoids the vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.51% (0.00512) | 41.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.51% (0.00505) | 38.95th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00031) | 5.77th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 16.02th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.04% (0.00045) | 14.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00045) | 12.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.03% (0.01034) | 39.91th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.03% (0.01034) | 37.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.09% (0.03090) | 64.78th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.63% (0.08626) | 85.56th | v1 |
| Jan 6, 2022 | 8.63% (0.08626) | 85.39th | v1 |
| Sep 1, 2021 | 2.06% (0.02061) | 76.87th | v1 |
| Apr 14, 2021 | 2.06% (0.02061) | 0.00th | v1 |
References (11)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00008.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-25596 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1880137 Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4JRXMKEMQRQYWYEPHVBIWUEAVQ3LU4FN/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA633Y3G5KX7MKRN4PFEGM3IVTJMBEOM/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJZERRBJN6E6STDCHT4JHP4MI6TKBCJE/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-25596
- https://security.gentoo.org/glsa/202011-06 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25596
- https://www.debian.org/security/2020/dsa-4769 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://xenbits.xen.org/xsa/advisory-339.html x_refsource_MISCPatchVendor Advisory
Change history (0)
No recorded changes yet.