Database/Kernel, userspace & hypervisor

Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write path
Impact
Buffer overflow on the MSI-X table write path for a passed-through device. A tenant with an MSI-X-capable device - which is every modern GPU and every modern NIC - writes past the end of the device model's MSI-X entry array and takes over the QEMU process. Without a device-model stub domain that process runs in dom0, so this is a direct guest-to-host escape reached through the ordinary act of a driver configuring its own interrupts. It is the most GPU-passthrough-specific escape of the pre-2018 era: the vulnerable code exists only because the device is passed through.
Who can reach it
Guest administrator - the tenant - with an assigned MSI-X-capable physical PCI device. Triggered from the guest's own device driver writing its MSI-X table.
What to do
Patch per XSA-164 and restart the affected device models, which means stopping and restarting every guest holding a passed-through device on that host - a full node drain, not a live migration, since migrating a VM with an assigned device is not generally possible. The structural mitigation worth adopting is running the device model in a stub domain so a device-model compromise lands in a deprivileged domain rather than dom0; on qemu-xen-traditional that was frequently not the default.
References
Related entries
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
- QEMU (virtio-net): Map leaking on error during receive - guest-triggered host memory exhaustion / DoSCVE-2022-26353 · QEMU (virtio-net)High
- OpenSSL 3.0: X.509 email-address punycode buffer overflow (4-byte stack overflow)CVE-2022-3602 · OpenSSL 3.0High
- OpenSSL 3.0: X.509 email-address variable-length buffer overflow (DoS)CVE-2022-3786 · OpenSSL 3.0High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.