TROYANOSYVIRUS
Back to CVEs

CVE-2020-15852

HIGH
7.8

Description

An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.

CVE Details

CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published7/20/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

linux:linux_kernelnetapp:cloud_backupnetapp:solidfire_baseboard_management_controllernetapp:steelstore_cloud_integrated_storagexen:xen

Weaknesses (CWE)

CWE-276

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.