Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-25597

EPSS 0.11% · P29
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-25597

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, will not become invalid over the life time of a guest. However, operations like the resetting of all event channels may involve decreasing one of the bounds checked when determining validity. This may lead to bug checks triggering, crashing the host. An unprivileged guest may be able to crash Xen, leading to a Denial of Service (DoS) for the entire system. All Xen versions from 4.4 onwards are vulnerable. Xen versions 4.3 and earlier are not vulnerable. Only systems with untrusted guests permitted to create more than the default number of event channels are vulnerable. This number depends on the architecture and type of guest. For 32-bit x86 PV guests, this is 1023; for 64-bit x86 PV guests, and for all ARM guests, this number is 4095. Systems where untrusted guests are limited to fewer than this number are not vulnerable. Note that xl and libxl limit max_event_channels to 1023 by default, so systems using exclusively xl, libvirt+libxl, or their own toolstack based on libxl, and not explicitly setting max_event_channels, are not vulnerable.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Xen 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Xen是英国剑桥大学的一款开源的虚拟机监视器产品。该产品能够使不同和不兼容的操作系统运行在同一台计算机上,并支持在运行时进行迁移,保证正常运行并且避免宕机。 Xen 4.14版本及之前版本中存在安全漏洞。该漏洞源于事件通道未转为无效时的错误引起的。攻击者可以利用该漏洞导致主机崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2020-25597

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-25597

登录查看更多情报信息。

Same Patch Batch · n/a · 2020-09-23 · 28 CVEs total

CVE-2020-25739Ruby 跨站脚本漏洞
CVE-2020-14370Docker 信息泄露漏洞
CVE-2020-25821peg-markdown 代码问题漏洞
CVE-2020-25826Windows PingID 安全漏洞
CVE-2020-14365Red Hat Ansible 数据伪造问题漏洞
CVE-2020-10714Red Hat WildFly Elytron 授权问题漏洞
CVE-2020-10687Red Hat Undertow 环境问题漏洞
CVE-2020-7122Aruba CX Switches 缓冲区错误漏洞
CVE-2020-7121Aruba CX 交换机 缓冲区错误漏洞
CVE-2020-24624HPE Pay 路径遍历漏洞
CVE-2020-24625HPE Pay 路径遍历漏洞
CVE-2020-24626HPE Pay 路径遍历漏洞
CVE-2020-16244APM Classic 安全漏洞
CVE-2020-16240GE APM Classic 安全漏洞
CVE-2020-25603Xen 安全漏洞
CVE-2020-24213YGOPro ygocore 输入验证错误漏洞
CVE-2020-5783IgniteNet HeliOS GLinq 跨站请求伪造漏洞
CVE-2020-5782IgniteNet HeliOS GLinq 输入验证错误漏洞
CVE-2020-5781IgniteNet HeliOS GLinq 跨站脚本漏洞
CVE-2020-25595Xen 安全漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-25597

No comments yet


Leave a comment