GPU VulnDB

Database/Kernel, userspace & hypervisor

Xen on AMD-Vi - IOMMU page mapping permissions: MULTI-TENANT ISOLATION: Third of the XSA-378 AMD-Vi mapping issues

CVE-2021-28696Kernel, userspace & hypervisorcurated

Impact

MULTI-TENANT ISOLATION: Third of the XSA-378 AMD-Vi mapping issues. Same practical consequence: a device assigned to one guest can reach memory it should not, defeating passthrough isolation.

Who can reach it

Guest with an assigned PCI device.

What to do

Fixed in Xen (XSA-378). Update and reboot; patch all three of the XSA-378 CVEs together.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.