GPU VulnDB

Database/Kernel, userspace & hypervisor

Xen PCI passthrough - device memory/IO decoding and host memory initialisation: With memory and I/O decoding left

CVE-2015-8553Kernel, userspace & hypervisorXSA-120curated

Impact

With memory and I/O decoding left disabled on an assigned device, reads that should have gone to the device instead return uninitialised host kernel memory to the guest. A tenant with a passed-through GPU sweeps its own BAR window and harvests whatever the host had in those pages - a pure cross-boundary confidentiality leak, silent, with no crash and no error counter to trip. It is the incomplete-fix follow-on to CVE-2015-0777 and the reason the XSA-120 family should be treated as an information-disclosure issue rather than only a DoS.

Who can reach it

Guest user with an assigned PCI device; reads its own device BARs while decoding is disabled.

What to do

Xen update per the XSA-120 family plus the corrected fix for CVE-2015-0777; host reboot. Because the leak is read-only and silent, there is no detection to fall back on - an operator cannot tell after the fact whether a tenant harvested host memory, which is the argument for treating this as patch-now rather than accepting it until the next maintenance window.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.