CVE-2020-29479
xen - security update
描述
An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unfortunately, permissions were not checked for certain operations on the root node. Unprivileged guests can get and modify permissions, list, and delete the root node. (Deleting the whole xenstore tree is a host-wide denial of service.) Achieving xenstore write access is also possible. All systems using oxenstored are vulnerable. Building and using oxenstored is the default in the upstream Xen distribution, if the Ocaml compiler is available. Systems using C xenstored are not vulnerable.
如何修補 CVE-2020-29479
要修補 CVE-2020-29479,請將受影響套件升級到下列已修補版本。
- —升級至 4.13.2-r3 或更新版本
- —升級至 4.14.0+88-g1d1d1f5391-1 或更新版本
- —升級至 4.11.4+57-g41a822c392-2 或更新版本
CVE-2020-29479 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 4.13.2-r3
- from 0, < 4.14.0+88-g1d1d1f5391-1
- from 0, < 4.11.4+57-g41a822c392-2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |