---
title: "CVE-2020-25601\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-25601?format=md
keywords: index, follow
---

# CVE-2020-25601

Publication date 23 September 2020

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2020-25601?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in Xen through 4.14.x. There is a lack of
preemption in evtchn\_reset() / evtchn\_destroy(). In particular, the FIFO
event channel model allows guests to have a large number of event channels
active at a time. Closing all of these (when resetting all event channels
or when cleaning up after the guest) may take extended periods of time. So
far, there was no arrangement for preemption at suitable intervals,
allowing a CPU to spend an almost unbounded amount of time in the
processing of these operations. Malicious or buggy guest kernels can mount
a Denial of Service (DoS) attack affecting the entire system. All Xen
versions are vulnerable in principle. Whether versions 4.3 and older are
vulnerable depends on underlying hardware characteristics.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2020-25601?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| xen | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Fixed 4.11.3+24-g14b62ab3e5-1ubuntu2.3 |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

hypervisor packages are in universe. For
issues in the hypervisor, add appropriate
tags to each section, ex:
Tags\_xen: universe-binary

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25601)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-25601)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-25601)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-25601)

### Related Ubuntu Security Notices (USN)

+ [USN-5617-1](https://usn.ubuntu.com/USN-5617-1)
+ Xen vulnerabilities
+ 19 September 2022

### Other references

* <https://xenbits.xen.org/xsa/advisory-344.html>
* <https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4JRXMKEMQRQYWYEPHVBIWUEAVQ3LU4FN/>
* <https://www.cve.org/CVERecord?id=CVE-2020-25601>
