Database/Kernel, userspace & hypervisor

Xen PCI passthrough - device memory/IO decoding and host memory initialisation: With memory and I/O decoding left
Impact
With memory and I/O decoding left disabled on an assigned device, reads that should have gone to the device instead return uninitialised host kernel memory to the guest. A tenant with a passed-through GPU sweeps its own BAR window and harvests whatever the host had in those pages - a pure cross-boundary confidentiality leak, silent, with no crash and no error counter to trip. It is the incomplete-fix follow-on to CVE-2015-0777 and the reason the XSA-120 family should be treated as an information-disclosure issue rather than only a DoS.
Who can reach it
Guest user with an assigned PCI device; reads its own device BARs while decoding is disabled.
What to do
Xen update per the XSA-120 family plus the corrected fix for CVE-2015-0777; host reboot. Because the leak is read-only and silent, there is no detection to fall back on - an operator cannot tell after the fact whether a tenant harvested host memory, which is the argument for treating this as patch-now rather than accepting it until the next maintenance window.
References
Related entries
- IBM GPFS kernel module (mmap path): An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file onCVE-2018-1782 · IBM GPFS kernel module (mmap path)Medium
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
- Intel CPU (Downfall / GDS): Downfall: Gather Data Sampling leaks AVX gather-instruction data across SMT siblingsCVE-2022-40982 · Intel CPU (Downfall / GDS)Medium
- Linux kernel (net/tls): A BPF sockmap psock could be attached to a socket that already had the kTLS ULP installed. TheCVE-2022-49732 · Linux kernel (net/tls)Medium
- AMD CPU (Zenbleed): Zenbleed: cross-process/cross-VM register-file data leak on Zen 2 at ~30 kB/s per core, no specialCVE-2023-20593 · AMD CPU (Zenbleed)Medium
- GPU local/shared memory not cleared between kernels (AMD, Apple, Qualcomm, Imagination): A GPU kernel reads whateverCVE-2023-4969 · GPU local/shared memory not cleared between kernels (AMD, Apple, Qualcomm, Imagination)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.