GPU VulnDB

Database/Kernel, userspace & hypervisor

Xen on AMD - x86 HVM pagetable height update: MULTI-TENANT ISOLATION: AMD HVM guest OS users can trigger

CVE-2019-19577Kernel, userspace & hypervisorcurated

Impact

MULTI-TENANT ISOLATION: AMD HVM guest OS users can trigger a data-structure access during a pagetable-height update, causing denial of service or possibly gaining privileges. Privilege escalation out of a guest into the hypervisor is the worst outcome available on a virtualised host - the attacker moves from one tenant's VM to controlling all of them.

Who can reach it

From inside an AMD HVM guest under Xen. Tenant-reachable.

What to do

Fixed in Xen (XSA-310). Update the hypervisor and reboot the host; no firmware step. Affects Xen through 4.12.x.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.