Database/Control plane, storage & DevOps
Linux swiotlb - info leak with DMA_FROM_DEVICE bounce buffers: The software IO TLB leaks information through bounce
Impact
The software IO TLB leaks information through bounce buffers on DMA_FROM_DEVICE transfers - stale buffer contents are exposed rather than being overwritten by the device. swiotlb is the bounce-buffer layer that SEV and SEV-SNP guests are forced to use for all DMA, because a confidential guest cannot let a device write directly into encrypted memory. So this leak sits precisely on the path every confidential VM's I/O takes, and what leaks is whatever the previous user of that bounce buffer left behind.
Who can reach it
Local, through DMA operations that use bounce buffers - which is all device I/O in an SEV/SNP guest, and any DMA above the device's addressing limit on a normal host.
What to do
Fixed in the Linux kernel. Distro kernel update plus reboot; no firmware step. Prioritise on confidential-computing hosts and inside confidential guest images, since SEV guests route all I/O through swiotlb by design.
References
Related entries
- Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and Windows: The keys LSA usesCVE-2023-4327 · Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and WindowsMedium
- Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code): On 64-bit platforms the pfn_to_kaddr() macroCVE-2023-52659 · Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code)Medium
- Linux perf/x86/amd/core - overflow status not cleared for unhandled indices: Unhandled overflow bits are left setCVE-2023-53073 · Linux perf/x86/amd/core - overflow status not cleared for unhandled indicesMedium
- Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errors: On AMD Zen systems, the InstructionCVE-2023-53438 · Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errorsMedium
- Linux i915 GVT-g mediated GPU virtualisation: Unsafe cleanup of per-vGPU debugfs state when a mediated vGPU isCVE-2023-53625 · Linux i915 GVT-g mediated GPU virtualisationMedium
- Citrix NetScaler ADC/Gateway: Code injection on the management interfaceCVE-2023-6548 · Citrix NetScaler ADC/GatewayMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.