CVE-2020-29568

CVSS v3.1 6.5 (Medium)
65% Progress
CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.04 % (15th)
0.04% Progress
Affected Products 2
Advisories 35

An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.

Weaknesses
CWE-770
Allocation of Resources Without Limits or Throttling
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2020-12-15 17:15:14
(3 years ago)
Updated Date
2022-04-26 16:12:15
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Xen 4.14.1 and prior versions cpe:2.3:o:xen:xen <= 4.14.1

Configuration #2

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...