Database/Firmware, BMC & network fabric

Linux KVM - PV TLB shootdown leaks memory between guest processes: In a KVM guest with paravirtualised TLB enabled, one
Impact
In a KVM guest with paravirtualised TLB enabled, one process in the guest can read memory belonging to another process in the same guest. The isolation that breaks is inside the VM rather than between VMs - which matters for any operator whose customers run multi-user workloads inside a single VM, and for confidential guests where the tenant assumed process separation held.
Who can reach it
Local, from one process to another inside a KVM guest with PV TLB enabled. The host must be running Linux with KVM.
What to do
Fixed in the Linux kernel. The fix belongs in the **guest** kernel, so update confidential and tenant VM images, not just hosts. Interim mitigation: disable PV TLB flush in the guest (the kvm.pv_tlb boot option / KVM_FEATURE_PV_TLB_FLUSH), which costs some scheduling efficiency and needs a guest reboot.
References
Related entries
- APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflectedCVE-2021-22810 · APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500Medium
- Arista EOS (TerminAttr / OpenConfig telemetry transport): The streaming-telemetry agent can leak MACsec keys over theCVE-2021-28509 · Arista EOS (TerminAttr / OpenConfig telemetry transport)Medium
- IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interfaceCVE-2021-38961 · IBM OpenBMC OP910 web UI (phosphor-webui lineage)Medium
- Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): A protection mechanism in 3rd and 4th generationCVE-2023-22655 · Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure)Medium
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingCVE-2023-40546 · shim (mok.c mirror_one_esl)Medium
- Linux kernel (drivers/pci/switch): If a userspace process is holding the Switchtec management character device openCVE-2023-52617 · Linux kernel (drivers/pci/switch)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.