Database/Kernel, userspace & hypervisor
Linux kernel drivers/vdpa/mlx5 (mlx5 vDPA net device): A guest with an assigned mlx5 vDPA net device sends an
Impact
A guest with an assigned mlx5 vDPA net device sends an unvalidated queue-pair-count control command and panics the host kernel. CVSS scope is Changed - this is a guest breaking out of its own blast radius into the hypervisor. On a multi-tenant node using mlx5 vDPA for accelerated guest networking, one tenant VM takes down every other VM on that host.
Who can reach it
A malicious virtio driver inside a guest VM with an mlx5 vDPA device, or any local process with access to /dev/vhost-vdpa (typically the qemu/kvm group). No host root required.
What to do
Upgrade the host kernel to 5.17, or a stable backport (5.15.29, 5.16.15) or your distro's patched kernel. Kernel upgrade means a rolling reboot of every hypervisor node using mlx5 vDPA, with live migration or workload drain per node. If you cannot reboot soon, stop exposing vDPA devices to untrusted guests - fall back to SR-IOV VFs or software virtio.
References
Related entries
- Intel CPU (Reptar): Redundant REX-prefix MOVSB causes unpredictable behaviourCVE-2023-23583 · Intel CPU (Reptar)High
- Intel i915 graphics driver for Linux (kernel < 6.2.10): A memory-buffer bounds failure in the i915 kernel driver thatCVE-2023-28410 · Intel i915 graphics driver for Linux (kernel < 6.2.10)High
- CephFS/RBD kernel client (libceph messenger v2): A signedness bug in net/ceph/messenger_v2.c turns an attacker-chosenCVE-2023-44466 · CephFS/RBD kernel client (libceph messenger v2)High
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theCVE-2023-52801 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu): The IOVA allocator's retry path overflows, so the lower-bound check is made against zeroCVE-2023-52910 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu/iommufd): An unmap runs off the end of the pinned page list and drops pin counts on pagesCVE-2023-53630 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.