VYPR
Medium severity5.5NVD Advisory· Published Dec 15, 2020· Updated Jun 17, 2026

CVE-2020-29485

CVE-2020-29485

Description

An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are not vulnerable.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • Xen/Xen2 versions
    cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*range: >=4.6.0,<=4.14.0
    • (no CPE)range: 4.6 - 4.14.x
  • Xen/Xendescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.