Database/Kernel, userspace & hypervisor

Xen on AMD-Vi - IOMMU page mapping permissions: Second of the XSA-378 IOMMU page-mapping issues on AMD-Vi. Incorrect
CVSS 6.8CVE-2021-28695Kernel, userspace & hypervisorcurated
Impact
Second of the XSA-378 IOMMU page-mapping issues on AMD-Vi. Incorrect mapping permissions give a passed-through device DMA reach beyond its guest, which is guest-to-host and guest-to-guest memory access via a device rather than via the CPU.
Who can reach it
Guest with a passed-through PCI device - the normal GPU-passthrough configuration.
What to do
Fixed in Xen (XSA-378). Hypervisor update plus host reboot.
References
Related entries
- Xen on AMD-Vi - IOMMU page mapping permissions: Third of the XSA-378 AMD-Vi mapping issues. Same practical consequenceCVE-2021-28696 · Xen on AMD-Vi - IOMMU page mapping permissionsMedium
- Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aCVE-2021-47230 · Linux kernel (arch/x86/kvm)Medium
- VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" groupCVE-2024-37085 · VMware ESXiMedium
- Linux kernel (drivers/pci): A Downstream Port Containment event and a device removal happening at the same time leaveCVE-2024-42302 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): A pci_slot holds an uncounted pointer to the pci_bus below it, and on hot removal the busCVE-2024-53194 · Linux kernel (drivers/pci)Medium
- OpenSSH (client): Machine-in-the-middle against the client when VerifyHostKeyDNS is enabledCVE-2025-26465 · OpenSSH (client)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.