Database/Kernel, userspace & hypervisor

Linux KVM x86 - stack out-of-bounds in ioapic_write_indirect(): A guest write to the virtual IOAPIC causes a stack
Impact
A guest write to the virtual IOAPIC causes a stack out-of-bounds access in the host kernel, reported by KASAN. At CVSS 8.8 this is a guest-to-host memory corruption primitive reachable by writing to an emulated device every VM has - stack corruption in the hypervisor is the shortest path from one tenant's VM to owning the machine and everything else on it.
Who can reach it
From inside a guest VM, by writing to the emulated IOAPIC. Tenant-reachable with no privilege beyond running a VM.
What to do
Fixed in the Linux kernel. Distro kernel update plus host reboot - no firmware, no VBIOS. Treat as top priority on any host running untrusted guest VMs.
References
Related entries
- Xen (xenstored): Guest can crash xenstored, taking down control-plane services for all guests on the hostCVE-2022-42309 · Xen (xenstored)High
- Linux kernel drivers/vdpa/mlx5 (mlx5 vDPA net device): A guest with an assigned mlx5 vDPA net device sends anCVE-2022-48864 · Linux kernel drivers/vdpa/mlx5 (mlx5 vDPA net device)High
- Intel CPU (Reptar): Redundant REX-prefix MOVSB causes unpredictable behaviourCVE-2023-23583 · Intel CPU (Reptar)High
- Intel i915 graphics driver for Linux (kernel < 6.2.10): A memory-buffer bounds failure in the i915 kernel driver thatCVE-2023-28410 · Intel i915 graphics driver for Linux (kernel < 6.2.10)High
- CephFS/RBD kernel client (libceph messenger v2): A signedness bug in net/ceph/messenger_v2.c turns an attacker-chosenCVE-2023-44466 · CephFS/RBD kernel client (libceph messenger v2)High
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theCVE-2023-52801 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.