---
title: "CVE-2020-25596\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-25596?format=md
keywords: index, follow
---

# CVE-2020-25596

Publication date 23 September 2020

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2020-25596?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can
experience denial of service via SYSENTER. The SYSENTER instruction leaves
various state sanitization activities to software. One of Xen's
sanitization paths injects a #GP fault, and incorrectly delivers it twice
to the guest. This causes the guest kernel to observe a kernel-privilege
#GP fault (typically fatal) rather than a user-privilege #GP fault (usually
converted into SIGSEGV/etc.). Malicious or buggy userspace can crash the
guest kernel, resulting in a VM Denial of Service. All versions of Xen from
3.2 onwards are vulnerable. Only x86 systems are vulnerable. ARM platforms
are not vulnerable. Only x86 systems that support the SYSENTER instruction
in 64bit mode are vulnerable. This is believed to be Intel, Centaur, and
Shanghai CPUs. AMD and Hygon CPUs are not believed to be vulnerable. Only
x86 PV guests can exploit the vulnerability. x86 PVH / HVM guests cannot
exploit the vulnerability.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2020-25596?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| xen | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Fixed 4.11.3+24-g14b62ab3e5-1ubuntu2.3 |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

hypervisor packages are in universe. For
issues in the hypervisor, add appropriate
tags to each section, ex:
Tags\_xen: universe-binary

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25596)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-25596)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-25596)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-25596)

### Related Ubuntu Security Notices (USN)

+ [USN-5617-1](https://usn.ubuntu.com/USN-5617-1)
+ Xen vulnerabilities
+ 19 September 2022

### Other references

* <https://xenbits.xen.org/xsa/advisory-339.html>
* <https://www.cve.org/CVERecord?id=CVE-2020-25596>
