Database/Kernel, userspace & hypervisor

Intel VT-d interrupt remapping engine as used by Xen 3.3.x-4.3.x: Proof that interrupt remapping is not a complete
Impact
Proof that interrupt remapping is not a complete containment boundary. A malformed MSI emitted by a bus-mastering device the tenant controls provokes a System Error Reporting NMI, and the NMI is delivered natively - it goes around the VT-d IR engine rather than through it - panicking the host. Every tenant on that node loses their work. The reason this belongs in a modern catalogue is architectural rather than historical: operators reason about passthrough safety as 'IOMMU plus IR equals isolated', and this is the canonical counterexample showing that error-reporting paths in the platform bypass the remapping engine entirely.
Who can reach it
A guest with a passed-through, bus-mastering-capable PCI device on an Intel VT-d host. Attack is on the host and therefore on every co-tenant.
What to do
Apply XSA-59 and reboot the hypervisor. Note the advisory's own framing - part of the mitigation is platform configuration of SERR/NMI handling, not just hypervisor code, so the fix needs to be validated per server model rather than assumed fleet-wide. For a GPU rental fleet the pragmatic control is to make host NMI-triggered panics a monitored, attributable event: if you cannot prevent a tenant from crashing the node, you should at least be able to tell which tenant did it and stop selling to them.
References
Related entries
- Xen 3.3.x-4.5.x and Linux kernel through 3.19.1 - PCI command register access for assigned devices: A tenant clears theCVE-2015-2150 · Xen 3.3.x-4.5.x and Linux kernel through 3.19.1 - PCI command register access for assigned devicesMedium
- Intel CPU (AEPIC Leak): Stale data read from the legacy xAPIC MMIO page - leaks SGX enclave and cross-domain dataCVE-2022-21233 · Intel CPU (AEPIC Leak)Medium
- Linux kernel (arch/x86/kvm/vmx): The return stack buffer was not refilled on VM exit when the host used IBRS/eIBRS asCVE-2022-49611 · Linux kernel (arch/x86/kvm/vmx)Medium
- AMD CPU (DIV0): Division-by-zero leaves stale quotient data readable across contexts - confidentiality loss on Zen 1CVE-2023-20588 · AMD CPU (DIV0)Medium
- KVM (nested VMX): Missing CR0/CR4 consistency checks in nVMX - L2 guest can break nested-virt assumptions / crash hostCVE-2023-30456 · KVM (nested VMX)Medium
- Linux kernel (drivers/iommu/intel): On device release VT-d could dereference a NULL domain and, separately, leave theCVE-2024-27079 · Linux kernel (drivers/iommu/intel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.