CVE-2020-29484 is a denial-of-service vulnerability affecting Xen through version 4.14.x, specifically the C xenstored component, and various distributions including Debian and Fedora. A malicious guest administrator can exploit a flaw in Xenstore watch event handling, where a large tag combined with writes to sub-paths can cause the watch event message payload to exceed 4096 bytes. This leads to an error condition and a NULL pointer dereference, crashing xenstored. The vulnerability has a CVSS score of 6.0 (Medium), indicating a local attack vector with low complexity, requiring high privileges to achieve a high impact on availability by rendering management operations impossible. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.14.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.