{"schema_version":"1.7.5","id":"CVE-2020-29568","published":"2020-12-15T17:15:14.660Z","modified":"2026-03-15T22:37:59.046126Z","related":["SUSE-SU-2021:0347-1","SUSE-SU-2021:0348-1","SUSE-SU-2021:0353-1","SUSE-SU-2021:0354-1","SUSE-SU-2021:0427-1","SUSE-SU-2021:0433-1","SUSE-SU-2021:0434-1","SUSE-SU-2021:0437-1","SUSE-SU-2021:0438-1","SUSE-SU-2021:0452-1","SUSE-SU-2021:0532-1","openSUSE-SU-2021:0075-1","openSUSE-SU-2021:0241-1"],"details":"An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.","affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29568.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"4.14.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"10.0"}]}]}}],"references":[{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202107-30"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4843"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/02/msg00018.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html"},{"type":"FIX","url":"https://xenbits.xenproject.org/xsa/advisory-349.html"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"}]}