Database/Firmware, BMC & network fabric

Linux KVM SEV API - host kernel crash from unprivileged guest creation: A non-root host user-level application can
Impact
A non-root host user-level application can crash the host kernel simply by creating a confidential guest through the KVM SEV API. Denial of service against the whole node from an unprivileged local process - on a GPU host that means every training job on the box dies because somebody with shell access called an ioctl.
Who can reach it
Local, **unprivileged** - the notable part. Only needs access to /dev/kvm, which on many hosts is more widely granted than people assume.
What to do
Fixed in the Linux kernel. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and reboot the host - no firmware, VBIOS or AGESA step. On a GPU fleet this is a cordon, drain and rolling reboot; plan it as normal kernel maintenance. Also audit who has /dev/kvm on your GPU hosts; if nothing on the node runs VMs, the device should not be world-accessible.
References
Related entries
- Intel processors (shared buffers data sampling): Incomplete cleanup of microarchitectural fill buffers lets a localCVE-2022-21125 · Intel processors (shared buffers data sampling)Medium
- Intel processors (post-barrier return stack buffer): PBRSB: return predictions made after an IBPB barrier can still useCVE-2022-26373 · Intel processors (post-barrier return stack buffer)Medium
- Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write accessCVE-2022-43309 · Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63Medium
- Linux kernel (drivers/infiniband/sw/rxe): Any tenant that can open an RDMA verbs device can oops the node. A queue-pairCVE-2022-50127 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- TPM 2.0 reference implementation: Out-of-bounds read in the same routine — disclosure of TPM-resident dataCVE-2023-1018 · TPM 2.0 reference implementationMedium
- Intel processors (return predictor target sharing): Return predictor targets are shared non-transparentlyCVE-2023-38575 · Intel processors (return predictor target sharing)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.