
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-27672 is a race condition vulnerability discovered in Xen through version 4.14.x, identified as XSA-345. The vulnerability was discovered by Hongyan Xia of Amazon and publicly disclosed on October 20, 2020. The issue affects Xen's hypervisor code that handles the updating of its own pagetables, specifically in the implementation of 2MiB and 1GiB superpages used to maximize TLB efficiency (Xen Advisory).
The vulnerability stems from race conditions in the Xen hypervisor's pagetable management code. The code attempts to use 2MiB and 1GiB superpages to maximize TLB efficiency, and to avoid lock contention, it tries to minimize the duration of lock holding during certain operations. However, several potential race conditions were not properly handled, which could allow precisely-timed guest actions to trigger a scenario where the code writes to a freed page that may have been already reused (Xen Advisory).
A malicious guest can exploit this vulnerability to cause a host denial-of-service. Additionally, data corruption or privilege escalation cannot be ruled out as potential impacts (Xen Advisory).
The vulnerability affects versions of Xen from at least 3.2 onward, but only on x86 systems - ARM systems are not vulnerable. Exploitation requires specific conditions: guests must have passed through hardware devices, and guests without passthrough configured cannot exploit the vulnerability. For HVM and PVH guests, exploitation is only possible when running in shadow mode on VT-x capable hardware (Intel, Centaur, and Shanghai CPUs) (Xen Advisory).
The primary mitigation is to run all guests in HVM or PVH mode with HAP enabled, which prevents exploitation of the vulnerability. For a permanent fix, system administrators should apply the appropriate patches provided in the security advisory. Various Linux distributions have released security updates addressing this vulnerability, including Debian, OpenSUSE, and Fedora (Debian Security, OpenSUSE Security, Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."