GPU VulnDB

Database/Kernel, userspace & hypervisor

QEMU xen_pt PCI passthrough config-space mediation (Xen 3.3.x-4.5.x): The device model failed to mediate guest writes

CVE-2015-4106Kernel, userspace & hypervisorXSA-131curated

Impact

The device model failed to mediate guest writes to PCI configuration space on passed-through devices, so a tenant reprograms registers the hypervisor believed it controlled - BARs, bus-mastering enables, capability structures. The advisory is explicit that privilege escalation, host crash and information leak all cannot be excluded. For a GPU rental business this is the fundamental mediation failure: config space is where the device's memory windows and DMA rights are declared, and letting a tenant edit it lets them redraw the map the IOMMU and the host were relying on.

Who can reach it

Guest administrator with an assigned PCI device, writing to its own device's PCI configuration space.

What to do

Apply XSA-131 and restart the device models - a node drain, because guests with assigned devices cannot be live-migrated off. Apply alongside XSA-126/CVE-2015-2756 (command-register access) and XSA-128/CVE-2015-4103 (MSI message data), which are the same mediation failure reached through different registers; they were issued separately but an operator should treat them as one change window.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.