Database/Kernel, userspace & hypervisor

QEMU xen_pt PCI passthrough config-space mediation (Xen 3.3.x-4.5.x): The device model failed to mediate guest writes
Impact
The device model failed to mediate guest writes to PCI configuration space on passed-through devices, so a tenant reprograms registers the hypervisor believed it controlled - BARs, bus-mastering enables, capability structures. The advisory is explicit that privilege escalation, host crash and information leak all cannot be excluded. For a GPU rental business this is the fundamental mediation failure: config space is where the device's memory windows and DMA rights are declared, and letting a tenant edit it lets them redraw the map the IOMMU and the host were relying on.
Who can reach it
Guest administrator with an assigned PCI device, writing to its own device's PCI configuration space.
What to do
Apply XSA-131 and restart the device models - a node drain, because guests with assigned devices cannot be live-migrated off. Apply alongside XSA-126/CVE-2015-2756 (command-register access) and XSA-128/CVE-2015-4103 (MSI message data), which are the same mediation failure reached through different registers; they were issued separately but an operator should treat them as one change window.
References
Related entries
- KVM (AMD SEV-ES): Out-of-bounds read/write in sev_es_string_io() - malicious SEV-ES guest corrupts host memoryCVE-2021-4093 · KVM (AMD SEV-ES)High
- VMware ESXi / Workstation / Fusion: Heap out-of-bounds write in the USB 2.0 EHCI controllerCVE-2022-31705 · VMware ESXi / Workstation / FusionHigh
- Linux kernel (eBPF verifier): Incorrect verifier pruning marks unsafe paths as safeCVE-2023-2163 · Linux kernel (eBPF verifier)High
- Linux kernel SMC-R (fallback path, DECLINE message leaking into the application stream): Silent data corruption, whichCVE-2023-52775 · Linux kernel SMC-R (fallback path, DECLINE message leaking into the application stream)High
- QEMU (virtio): DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMUCVE-2024-3446 · QEMU (virtio)High
- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordCVE-2024-58239 · Linux kernel (net/tls)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.