---
title: "CVE-2020-15565\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-15565?format=md
keywords: index, follow
---

# CVE-2020-15565

Publication date 7 July 2020

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2020-15565?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest
OS users to cause a host OS denial of service or possibly gain privileges
because of insufficient cache write-back under VT-d. When page tables are
shared between IOMMU and CPU, changes to them require flushing of both
TLBs. Furthermore, IOMMUs may be non-coherent, and hence prior to flushing
IOMMU TLBs, a CPU cache also needs writing back to memory after changes
were made. Such writing back of cached data was missing in particular when
splitting large page mappings into smaller granularity ones. A malicious
guest may be able to retain read/write DMA access to frames returned to
Xen's free pool, and later reused for another purpose. Host crashes
(leading to a Denial of Service) and privilege escalation cannot be ruled
out. Xen versions from at least 3.2 onwards are affected. Only x86 Intel
systems are affected. x86 AMD as well as Arm systems are not affected. Only
x86 HVM guests using hardware assisted paging (HAP), having a passed
through PCI device assigned, and having page table sharing enabled can
leverage the vulnerability. Note that page table sharing will be enabled
(by default) only if Xen considers IOMMU and CPU large page size support
compatible.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2020-15565?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| xen | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Fixed 4.11.3+24-g14b62ab3e5-1ubuntu2.3 |
| 19.10 eoan | Ignored end of life |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

hypervisor packages are in universe. For
issues in the hypervisor, add appropriate
tags to each section, ex:
Tags\_xen: universe-binary

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Changed |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15565)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-15565)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-15565)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-15565)

### Related Ubuntu Security Notices (USN)

+ [USN-5617-1](https://usn.ubuntu.com/USN-5617-1)
+ Xen vulnerabilities
+ 19 September 2022

### Other references

* <https://xenbits.xen.org/xsa/advisory-321.html>
* <http://www.openwall.com/lists/oss-security/2020/07/07/4>
* <http://xenbits.xen.org/xsa/advisory-321.html>
* <https://www.cve.org/CVERecord?id=CVE-2020-15565>
