CVE-2020-27672
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-27672 is a race condition vulnerability discovered in Xen through version 4.14.x, identified as XSA-345. The vulnerability was discovered by Hongyan Xia of Amazon and publicly disclosed on October 20, 2020. The issue affects Xen's hypervisor code that handles the updating of its own pagetables, specifically in the implementation of 2MiB and 1GiB superpages used to maximize TLB efficiency (Xen Advisory).

Technical details

The vulnerability stems from race conditions in the Xen hypervisor's pagetable management code. The code attempts to use 2MiB and 1GiB superpages to maximize TLB efficiency, and to avoid lock contention, it tries to minimize the duration of lock holding during certain operations. However, several potential race conditions were not properly handled, which could allow precisely-timed guest actions to trigger a scenario where the code writes to a freed page that may have been already reused (Xen Advisory).

Impact

A malicious guest can exploit this vulnerability to cause a host denial-of-service. Additionally, data corruption or privilege escalation cannot be ruled out as potential impacts (Xen Advisory).

Exploitability

The vulnerability affects versions of Xen from at least 3.2 onward, but only on x86 systems - ARM systems are not vulnerable. Exploitation requires specific conditions: guests must have passed through hardware devices, and guests without passthrough configured cannot exploit the vulnerability. For HVM and PVH guests, exploitation is only possible when running in shadow mode on VT-x capable hardware (Intel, Centaur, and Shanghai CPUs) (Xen Advisory).

Mitigation and workarounds

The primary mitigation is to run all guests in HVM or PVH mode with HAP enabled, which prevents exploitation of the vulnerability. For a permanent fix, system administrators should apply the appropriate patches provided in the security advisory. Various Linux distributions have released security updates addressing this vulnerability, including Debian, OpenSUSE, and Fedora (Debian Security, OpenSUSE Security, Fedora Update).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management