CVE-2020-11743
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 for success, and a negative number for errors. Some misplaced brackets cause one error path to return 1 instead of a negative value. The grant table code in Linux treats this condition as success, and proceeds with incorrectly initialised state. A buggy or malicious guest can construct its grant table in such a way that, when a backend domain tries to map a grant, it hits the incorrect error path. This will crash a Linux based dom0 or backend domain.
EPSS 0.09% · 26.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | xen | 4.9.2-0ubuntu7, 4.11.3+24-g14b62ab3e5-1ubuntu2.2, 4.11.3+24-g14b62ab3e5-1ubuntu2 |
| Ubuntu:16.04:LTS | xen | 4.5.1-0ubuntu1, 0, 4.6.0-1ubuntu4 |
| Ubuntu:18.04:LTS | xen | 4.9.0-0ubuntu3, 4.9.2-0ubuntu1, 4.9.0-0ubuntu4 |
Exploit Intelligence
- https://xenbits.xen.org/xsa/advisory-316.html (circl)
- http://xenbits.xen.org/xsa/advisory-316.html (circl)
- [oss-security] 20200414 Xen Security Advisory 316 v3 (CVE-2020-11743) - Bad error path in GNTTABOP_map_grant (circl)
- FEDORA-2020-440457afe4 (circl)
- FEDORA-2020-295ed0b1e0 (circl)
- openSUSE-SU-2020:0599 (circl)
- FEDORA-2020-cbc3149753 (circl)
- GLSA-202005-08 (circl)
- DSA-4723 (circl)
Timeline
- Apr 14, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-11743 third-party-advisory
- https://xenbits.xen.org/xsa/advisory-316.html third-party-advisory
- http://www.openwall.com/lists/oss-security/2020/04/14/3 third-party-advisory
- http://xenbits.xen.org/xsa/advisory-316.html third-party-advisory
- https://ubuntu.com/security/notices/USN-5617-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-11743 third-party-advisory