Database/Kernel, userspace & hypervisor

Xen - x86 PV guest denial of service via SYSENTER: SYSENTER leaves state sanitisation to software, and on AMD hardware
CVSS 5.5CVE-2020-25596Kernel, userspace & hypervisorcurated
Impact
SYSENTER leaves state sanitisation to software, and on AMD hardware Xen's PV guest handling got it wrong, letting a PV guest kernel deny service to itself and destabilise the host path. Legacy PV territory, included for completeness of the Xen-on-AMD picture.
Who can reach it
From inside an x86 PV guest.
What to do
Fixed in Xen (XSA-339). Hypervisor update plus host reboot. The durable answer is to stop running PV guests - HVM/PVH is the supported path and carries less of this legacy surface.
References
Related entries
- Xen on x86 - speculative vulnerabilities with bare 32-bit PV guests: Bare (non-shim) 32-bit PV guests run in ring 1, anCVE-2021-28689 · Xen on x86 - speculative vulnerabilities with bare 32-bit PV guestsMedium
- Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identityCVE-2021-47140 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2021-47410 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDCVE-2021-47420 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- util-linux (chfn/chsh): Partial disclosure of arbitrary files via libreadline in setuid chfn/chshCVE-2022-0563 · util-linux (chfn/chsh)Medium
- KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast() - guest crashes the hostCVE-2022-2153 · KVMMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.