← Zuruck zu CVEs
CVE-2020-15852
HIGH7.8
Beschreibung
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
CVE Details
CVSS v3.1 Bewertung7.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht7/20/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
linux:linux_kernelnetapp:cloud_backupnetapp:solidfire_baseboard_management_controllernetapp:steelstore_cloud_integrated_storagexen:xen
Schwachen (CWE)
CWE-276
Referenzen
http://www.openwall.com/lists/oss-security/2020/07/21/2(cve@mitre.org)
http://xenbits.xen.org/xsa/advisory-329.html(cve@mitre.org)
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cadfad870154e14f745ec845708bc17d166065f2(cve@mitre.org)
https://security.netapp.com/advisory/ntap-20200810-0001/(cve@mitre.org)
http://www.openwall.com/lists/oss-security/2020/07/21/2(af854a3a-2127-422b-91ae-364da2661108)
http://xenbits.xen.org/xsa/advisory-329.html(af854a3a-2127-422b-91ae-364da2661108)
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cadfad870154e14f745ec845708bc17d166065f2(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/torvalds/linux/commit/cadfad870154e14f745ec845708bc17d166065f2(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20200810-0001/(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.