CVE-2020-25598
Description
A security flaw was found in Xen. This flaw allows a buggy or malicious HVM subdomain to cause an RCU reference to be leaked. This issue causes subsequent administration operations on the host to livelock, resulting in a denial of service (DoS). The highest threat from this vulnerability is to system availability.
Statement
This issue can generally only be exploited by x86 HVM guests, as these are the only type of VM which have a QEMU stubdomain. x86 PV and PVH domains, as well as ARM guests typically don't use a stubdomain. Additionally, VMs using PV stubdomains or with emulators running in dom0 cannot exploit the vulnerability.
Xen 4.14 and later versions are vulnerable to this flaw. Red Hat Enterprise Linux 5 is not affected, as it shipped an older version of Xen which did not include the buggy code path.
Mitigation
Reconfiguring x86 HVM guests to use a PV or no stubdomain will mitigate the vulnerability.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.5 | 5.5 | N/A |
| Attack Vector | Local | Local | N/A |
| Attack Complexity | Low | Low | N/A |
| Privileges Required | Low | Low | N/A |
| User Interaction | None | None | N/A |
| Scope | Changed | Unchanged | N/A |
| Confidentiality | None | None | N/A |
| Integrity Impact | None | None | N/A |
| Availability Impact | High | High | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU)
Inconsistent locking discipline can lead to deadlock.
Acknowledgements
Red Hat would like to thank the Xen project for reporting this issue.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.