Medium severity6.2NVD Advisory· Published Dec 15, 2020· Updated Jun 17, 2026
CVE-2020-29570
CVE-2020-29570
Description
An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting the entire system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
35- Range: <=4.14.x
- osv-coords29 versionspkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/xen&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/opensuse/xen&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/xen&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/opensuse/xen&distro=openSUSE%20Tumbleweedpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/opensuse/xen&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSS
< 4.10.4_24-3.53.1+ 28 more
- (no CPE)range: < 4.10.4_24-3.53.1
- (no CPE)range: < 4.10.4_24-3.53.1
- (no CPE)range: < 4.9.4_16-3.80.1
- (no CPE)range: < 4.13.2_06-lp152.2.21.1
- (no CPE)range: < 4.12.4_06-3.36.1
- (no CPE)range: < 4.12.4_06-3.40.1
- (no CPE)range: < 4.7.6_14-43.73.1
- (no CPE)range: < 4.7.6_14-43.73.1
- (no CPE)range: < 4.7.6_14-43.73.1
- (no CPE)range: < 4.11.4_16-2.48.1
- (no CPE)range: < 4.11.4_16-2.48.1
- (no CPE)range: < 4.13.2_06-3.22.1
- (no CPE)range: < 4.10.4_24-3.53.1
- (no CPE)range: < 4.9.4_16-3.80.1
- (no CPE)range: < 4.9.4_16-3.80.1
- (no CPE)range: < 4.9.4_16-3.80.1
- (no CPE)range: < 4.9.4_16-3.80.1
- (no CPE)range: < 4.13.2_06-3.22.1
- (no CPE)range: < 4.15.1_01-1.2
- (no CPE)range: < 4.4.4_48-61.61.1
- (no CPE)range: < 4.12.4_06-3.40.1
- (no CPE)range: < 4.12.4_06-lp151.2.36.1
- (no CPE)range: < 4.12.4_06-3.36.1
- (no CPE)range: < 4.12.4_06-3.36.1
- (no CPE)range: < 4.7.6_14-43.73.1
- (no CPE)range: < 4.11.4_16-2.48.1
- (no CPE)range: < 4.11.4_16-2.48.1
- (no CPE)range: < 4.9.4_16-3.80.1
- (no CPE)range: < 4.9.4_16-3.80.1
- Xen/Xendescription
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- xenbits.xenproject.org/xsa/advisory-358.htmlnvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2020/12/16/4nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202107-30nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4812nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2C6M6S3CIMEBACH6O7V4H2VDANMO6TVA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OBLV6L6Q24PPQ2CRFXDX4Q76KU776GKI/nvd
News mentions
0No linked articles in our index yet.