GPU VulnDB

Database/Kernel, userspace & hypervisor

Xen on AMD-Vi - IOMMU page mapping permissions: MULTI-TENANT ISOLATION: Second of the XSA-378 IOMMU page-mapping issues

CVE-2021-28695Kernel, userspace & hypervisorcurated

Impact

MULTI-TENANT ISOLATION: Second of the XSA-378 IOMMU page-mapping issues on AMD-Vi. Incorrect mapping permissions give a passed-through device DMA reach beyond its guest, which is guest-to-host and guest-to-guest memory access via a device rather than via the CPU.

Who can reach it

Guest with a passed-through PCI device - the normal GPU-passthrough configuration.

What to do

Fixed in Xen (XSA-378). Hypervisor update plus host reboot.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.