CVE-2020-15563
NixOS vulnerability analysis and mitigation

Overview

An inverted conditional vulnerability was discovered in Xen versions 4.8 through 4.13.x, identified as CVE-2020-15563. The vulnerability affects x86 HVM guests' dirty video RAM tracking code, allowing guests to make Xen dereference a pointer that points to unmapped space. This issue was discovered by Jan Beulich of SUSE and was publicly disclosed on July 7, 2020 (Xen Advisory).

Technical details

The vulnerability specifically affects x86 systems running HVM guests that use shadow paging. For the vulnerability to be exploitable, there needs to be an entity actively monitoring a guest's video frame buffer, typically for display purposes. The issue does not affect Arm systems, x86 PV guests, or x86 HVM guests using hardware assisted paging (HAP) (Xen Advisory).

Impact

A malicious or buggy HVM guest can cause the hypervisor to crash, resulting in a Denial of Service (DoS) that affects the entire host system (Xen Advisory, Ubuntu Notice).

Exploitability

The vulnerability can be leveraged by x86 HVM guests using shadow paging when there is an entity actively monitoring the guest's video frame buffer. The exploitation requires specific conditions to be met, including the use of shadow paging instead of hardware assisted paging (Xen Advisory).

Mitigation and workarounds

Several mitigation options are available: running only PV guests will avoid the vulnerability entirely, or for HVM guests explicitly configured to use shadow paging, changing to HAP (by setting 'hap=1' in the configuration) will prevent exposure to the vulnerability. HAP is the default setting in upstream Xen where hardware supports it. The vulnerability can also be resolved by applying the security patches provided (Xen Advisory).

Community reactions

Multiple Linux distributions released security updates to address this vulnerability, including Debian, Ubuntu, Fedora, and Gentoo. Citrix also released a security update for their Citrix Hypervisor product (Debian Notice, Citrix Update).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util-bdb
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util-ldap
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util-ldap
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util-sqlite
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management