GPU VulnDB

Database/Kernel, userspace & hypervisor

Xen on AMD-Vi - IOMMU page mapping permissions: Third of the XSA-378 AMD-Vi mapping issues. Same practical consequence

CVE-2021-28696Kernel, userspace & hypervisorcurated

Impact

Third of the XSA-378 AMD-Vi mapping issues. Same practical consequence: a device assigned to one guest can reach memory it should not, defeating passthrough isolation.

Who can reach it

Guest with an assigned PCI device.

What to do

Fixed in Xen (XSA-378). Update and reboot; patch all three of the XSA-378 CVEs together.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.