← Retour aux CVEs
CVE-2020-15852
HIGH7.8
Description
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.
Details CVE
Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie7/20/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
linux:linux_kernelnetapp:cloud_backupnetapp:solidfire_baseboard_management_controllernetapp:steelstore_cloud_integrated_storagexen:xen
Faiblesses (CWE)
CWE-276
References
http://www.openwall.com/lists/oss-security/2020/07/21/2(cve@mitre.org)
http://xenbits.xen.org/xsa/advisory-329.html(cve@mitre.org)
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cadfad870154e14f745ec845708bc17d166065f2(cve@mitre.org)
https://security.netapp.com/advisory/ntap-20200810-0001/(cve@mitre.org)
http://www.openwall.com/lists/oss-security/2020/07/21/2(af854a3a-2127-422b-91ae-364da2661108)
http://xenbits.xen.org/xsa/advisory-329.html(af854a3a-2127-422b-91ae-364da2661108)
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=cadfad870154e14f745ec845708bc17d166065f2(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/torvalds/linux/commit/cadfad870154e14f745ec845708bc17d166065f2(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20200810-0001/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.