CVE-2020-27674 PUBLISHED

An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.

EPSS 0.07% · 22.1th percentile

Risk Scores

EPSS Score
0.07%
22.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSxen0, 4.5.1-0ubuntu1, 4.5.1-0ubuntu2
Ubuntu:20.04:LTSxen4.11.3+24-g14b62ab3e5-1ubuntu2.3, 4.9.2-0ubuntu7, 4.11.3+24-g14b62ab3e5-1ubuntu1
Ubuntu:18.04:LTSxen4.9.0-0ubuntu3, 4.9.0-0ubuntu4, 4.9.2-0ubuntu1

Timeline

References

Open in Interactive Console →