ALPINE-CVE-2020-29481
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because all Xenstore entries of a guest below /local/domain/<domid> are being deleted by Xen tools when a guest is destroyed, only Xenstore entries of other guests still running are affected. For example, a newly created guest domain might be able to read sensitive information that had belonged to a previously existing guest domain. Both Xenstore implementations (C and Ocaml) are vulnerable.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.18 | xen | 4.9.1-r3, 4.9.1-r2, 4.9.1-r1 |
| Alpine:v3.16 | xen | 4.12.1-r2, 4.0.1-r0, 4.0.1-r1 |
| Alpine:v3.13 | xen | 4.12.0-r3, 0, 4.0.1-r1 |
| Alpine:v3.21 | xen | 4.0.1-r0, 0, 4.9.1-r3 |
| Alpine:v3.17 | xen | 0, 4.0.1-r0, 4.0.1-r2 |
| Alpine:v3.11 | xen | 4.10.0-r3, 0, 4.0.1-r0 |
| Alpine:v3.14 | xen | 0, 4.4.1-r5, 4.4.1-r6 |
| Alpine:v3.20 | xen | 4.6.0-r2, 0, 4.9.1-r3 |
| Alpine:v3.22 | xen | 4.9.1-r3, 0, 4.0.1-r0 |
| Alpine:v3.19 | xen | 0, 4.0.1-r0, 4.0.1-r1 |
| Alpine:v3.23 | xen | 0, 0, 4.0.1-r0 |
| Alpine:v3.15 | xen | 4.6.1-r1, 4.9.1-r3, 4.9.1-r2 |
| Alpine:v3.12 | xen | 0, 0, 4.0.1-r0 |
| Alpine:v3.24 | xen | 0 |
Timeline
- Dec 15, 2020 CVE Published
- Apr 30, 2026 Distribution Patch
- Jun 15, 2026 CVE Updated