Database/Kernel, userspace & hypervisor

Xen on AMD-Vi - IOMMU page mapping permissions: Third of the XSA-378 AMD-Vi mapping issues. Same practical consequence
CVE-2021-28696Kernel, userspace & hypervisorcurated
Impact
Third of the XSA-378 AMD-Vi mapping issues. Same practical consequence: a device assigned to one guest can reach memory it should not, defeating passthrough isolation.
Who can reach it
Guest with an assigned PCI device.
What to do
Fixed in Xen (XSA-378). Update and reboot; patch all three of the XSA-378 CVEs together.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.