CVE-2020-29040: Xen
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one error. NOTE: this issue is caused by an incorrect fix for CVE-2020-27671.
Affected products
- Xen Xen: up to and including 4.14.0
Published 2020-11-24. Last modified 2026-06-17.