Database/Kernel, userspace & hypervisor

Linux KVM (arch/x86/kvm/svm.c, vmx.c) and Xen 4.3.x-4.6.x - #AC exception handling: A guest raises alignment-check
Impact
A guest raises alignment-check exceptions in a tight loop and the host panics or hangs. No exploit chain, no memory corruption, no privilege needed inside the guest beyond running instructions - a few lines of assembly from an unprivileged process in any tenant VM takes down the whole physical machine and every co-tenant's workload with it. For a GPU cloud where one node carries eight accelerators and potentially several tenants, this is the cheapest possible cross-tenant availability attack and it hits KVM and Xen alike.
Who can reach it
Guest OS user - not even guest administrator - in any VM on the host. Unprivileged code inside the tenant's own guest is sufficient.
What to do
Kernel update for KVM hosts, XSA-156 patches for Xen; both need a host reboot with tenants evacuated. There is no configuration workaround - you cannot disable #AC delivery - so unpatched hosts simply have this exposure. Given how trivially triggerable it is, treat it as a gating check before a host is allowed to accept multi-tenant placement, rather than something to schedule into a routine patch cycle.
References
Related entries
- Xen PCI passthrough - device memory/IO decoding and host memory initialisation: With memory and I/O decoding leftCVE-2015-8553 · Xen PCI passthrough - device memory/IO decoding and host memory initialisationMedium
- IBM GPFS kernel module (mmap path): An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file onCVE-2018-1782 · IBM GPFS kernel module (mmap path)Medium
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
- Intel CPU (Downfall / GDS): Downfall: Gather Data Sampling leaks AVX gather-instruction data across SMT siblingsCVE-2022-40982 · Intel CPU (Downfall / GDS)Medium
- Linux kernel (net/tls): A BPF sockmap psock could be attached to a socket that already had the kTLS ULP installed. TheCVE-2022-49732 · Linux kernel (net/tls)Medium
- AMD CPU (Zenbleed): Zenbleed: cross-process/cross-VM register-file data leak on Zen 2 at ~30 kB/s per core, no specialCVE-2023-20593 · AMD CPU (Zenbleed)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.