Medium severity5.3NVD Advisory· Published Oct 22, 2020· Updated Jun 17, 2026
CVE-2020-27674
CVE-2020-27674
Description
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34- Xen/Xendescription
- osv-coords26 versionspkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/opensuse/xen&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/xen&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/opensuse/xen&distro=openSUSE%20Tumbleweedpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/opensuse/xen&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/xen&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL
< 4.10.4_22-3.50.1+ 25 more
- (no CPE)range: < 4.10.4_22-3.50.1
- (no CPE)range: < 4.9.4_14-3.77.1
- (no CPE)range: < 4.11.4_14-2.45.1
- (no CPE)range: < 4.11.4_14-2.45.1
- (no CPE)range: < 4.13.2_04-lp152.2.18.1
- (no CPE)range: < 4.12.4_04-3.37.1
- (no CPE)range: < 4.12.4_04-3.37.1
- (no CPE)range: < 4.13.2_04-3.19.1
- (no CPE)range: < 4.13.2_04-3.19.1
- (no CPE)range: < 4.10.4_22-3.50.1
- (no CPE)range: < 4.9.4_14-3.77.1
- (no CPE)range: < 4.9.4_14-3.77.1
- (no CPE)range: < 4.9.4_14-3.77.1
- (no CPE)range: < 4.9.4_14-3.77.1
- (no CPE)range: < 4.11.4_14-2.45.1
- (no CPE)range: < 4.11.4_14-2.45.1
- (no CPE)range: < 4.15.1_01-1.2
- (no CPE)range: < 4.4.4_46-61.58.1
- (no CPE)range: < 4.10.4_22-3.50.1
- (no CPE)range: < 4.12.4_04-lp151.2.33.1
- (no CPE)range: < 4.9.4_14-3.77.1
- (no CPE)range: < 4.9.4_14-3.77.1
- (no CPE)range: < 4.7.6_12-43.70.1
- (no CPE)range: < 4.7.6_12-43.70.1
- (no CPE)range: < 4.7.6_12-43.70.1
- (no CPE)range: < 4.7.6_12-43.70.1
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- Range: <=4.14.x
Patches
Vulnerability mechanics
References
7- xenbits.xen.org/xsa/advisory-286.htmlnvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2021/01/19/5nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202011-06nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4804nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZAM3LYJ5TZLSSNL3KXFILM46QKVTOUA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3U4LNKKXU4UP4Z5XP6TMIWSML3QODPE/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XIK57QJOVOPWH6RFRNMGOBCROBCKMDG2/nvd
News mentions
0No linked articles in our index yet.