CVE-2020-27673

low
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
2.5

Description

An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2020-27673 NameCVE-2020-27673 DescriptionAn issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues,…

CVE-2020-27673

NameCVE-2020-27673
DescriptionAn issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2483-1, DLA-2494-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.257-1fixed
bookworm6.1.170-3fixed
bookworm (security)6.1.172-1fixed
trixie6.12.86-1fixed
trixie (security)6.12.90-1fixed
forky7.0.9-1fixed
sid7.0.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcestretch4.9.246-1DLA-2494-1
linuxsourcebuster4.19.160-1
linuxsource(unstable)5.9.6-1
linux-4.19sourcestretch4.19.160-2~deb9u1DLA-2483-1

Notes

https://xenbits.xen.org/xsa/advisory-332.html

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://xenbits.xen.org/xsa/advisory-332.html

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected
arch Arch Fixed 1 release
VersionStatusFixed in
Fixed 5.9.2.arch1-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 5.9.6-1
sid Fixed 5.9.6-1
forky Fixed 5.9.6-1
bullseye Fixed 5.9.6-1
bookworm Fixed 5.9.6-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.