Database/Kernel, userspace & hypervisor

Xen Intel VT-d IOMMU page-table handling for PCI passthrough: An inverted boolean means Xen clears a present IOMMU
Impact
An inverted boolean means Xen clears a present IOMMU translation entry without flushing the IOMMU TLB. The device keeps translating through the stale cached mapping, so a passed-through GPU continues DMA-ing into host or previous-tenant memory after the mapping that authorised it has been revoked. This is the failure mode operators most underestimate: the IOMMU page tables look correct in memory while the hardware is still using an older view of them. In a cluster that recycles GPUs between tenants, stale IOMMU cache entries are exactly how tenant N reaches tenant N-1's pages.
Who can reach it
A guest administrator with a passed-through PCI device, arranging for mappings to be torn down while its device continues issuing DMA.
What to do
Patch Xen 4.2.x/4.3.x per XSA-78 and reboot the hypervisor - IOMMU flush logic is not something that can be corrected at runtime. Pair the patch with the companion issue CVE-2013-6400 (XSA-80), which leaves the flush-suppression flag set on an error path and produces the same stale-mapping condition by a different route; patching one without the other leaves the hole open. Requires evacuating every tenant on the node.
References
Related entries
- QEMU xen_pt PCI passthrough config-space mediation (Xen 3.3.x-4.5.x): The device model failed to mediate guest writesCVE-2015-4106 · QEMU xen_pt PCI passthrough config-space mediation (Xen 3.3.x-4.5.x)High
- KVM (AMD SEV-ES): Out-of-bounds read/write in sev_es_string_io() - malicious SEV-ES guest corrupts host memoryCVE-2021-4093 · KVM (AMD SEV-ES)High
- VMware ESXi / Workstation / Fusion: Heap out-of-bounds write in the USB 2.0 EHCI controllerCVE-2022-31705 · VMware ESXi / Workstation / FusionHigh
- Linux kernel (eBPF verifier): Incorrect verifier pruning marks unsafe paths as safeCVE-2023-2163 · Linux kernel (eBPF verifier)High
- Linux kernel SMC-R (fallback path, DECLINE message leaking into the application stream): Silent data corruption, whichCVE-2023-52775 · Linux kernel SMC-R (fallback path, DECLINE message leaking into the application stream)High
- QEMU (virtio): DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMUCVE-2024-3446 · QEMU (virtio)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.