Database/Kernel, userspace & hypervisor

Xen on AMD - x86 HVM pagetable height update: AMD HVM guest OS users can trigger a data-structure access during a
CVSS 7.2CVE-2019-19577Kernel, userspace & hypervisorcurated
Impact
AMD HVM guest OS users can trigger a data-structure access during a pagetable-height update, causing denial of service or possibly gaining privileges. Privilege escalation out of a guest into the hypervisor is the worst outcome available on a virtualised host - the attacker moves from one tenant's VM to controlling all of them.
Who can reach it
From inside an AMD HVM guest under Xen. Tenant-reachable.
What to do
Fixed in Xen (XSA-310). Update the hypervisor and reboot the host; no firmware step. Affects Xen through 4.12.x.
References
Related entries
- IBM Spectrum Scale kernel module: An unauthenticated local trigger takes down the Spectrum Scale kernel module and withCVE-2020-4411 · IBM Spectrum Scale kernel moduleHigh
- Xen - x86 IOMMU command timeout detection and handling: Xen's IOMMU command timeout handling is inappropriate, so IOMMUCVE-2021-28692 · Xen - x86 IOMMU command timeout detection and handlingHigh
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2021-4460 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Xen (x86): Unintended memory sharing between guests - cross-tenant data exposureCVE-2022-42327 · Xen (x86)High
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
- Linux kernel (drivers/vfio/pci/hisilicon): The VFIO migration save and resume paths do not advance the data pointer byCVE-2023-52453 · Linux kernel (drivers/vfio/pci/hisilicon)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.