Database/Firmware, BMC & network fabric

Xen on older AMD CPUs - 64-bit PV guest processor erratum: Xen 4.0 and 4.1 running a 64-bit PV guest on older AMD CPUs
Impact
Xen 4.0 and 4.1 running a 64-bit PV guest on older AMD CPUs did not protect against a processor erratum, letting a guest OS user hang the host. Historical, but it is the earliest entry in a long pattern worth naming: AMD CPU errata that a hypervisor must actively work around, where forgetting the workaround hands guests a host-availability lever.
Who can reach it
From inside a 64-bit PV guest on affected legacy AMD silicon.
What to do
Fixed in Xen (XSA-9). Hypervisor update plus reboot. Affected silicon is long retired; carried here for completeness of the AMD virtualisation history rather than as an action item.
References
Related entries
- AMD 16h processor microcode - locked instructions vs write-combined memory: Interaction between locked instructionsCVE-2013-6885 · AMD 16h processor microcode - locked instructions vs write-combined memoryUnscored
- Juniper Junos OS MACsec key configuration (CKN/CAK): If you configure a MACsec connectivity-association name or keyCVE-2018-0021 · Juniper Junos OS MACsec key configuration (CKN/CAK)Unscored
- swtpm (state blob header parsing): An invalid hdrsize in swtpm's saved state header causes an out-of-bounds accessCVE-2022-23645 · swtpm (state blob header parsing)Unscored
- Supermicro BMC (IPMI web interface): Part of the same 2023 Supermicro BMC web-interface batchCVE-2023-40286 · Supermicro BMC (IPMI web interface)Unscored
- Linux x86/srso - SRSO mitigation missing for Hygon processors: The kernel's Speculative Return Stack OverflowCVE-2023-52482 · Linux x86/srso - SRSO mitigation missing for Hygon processorsUnscored
- Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VMCVE-2023-54296 · Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migrationUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.