Database/Kernel, userspace & hypervisor

Xen on AMD - debug extensions (DBEXT) exposure to guests: AMD CPUs since roughly 2014 carry extensions to x86 debugging
CVE-2023-34327Kernel, userspace & hypervisorcurated
Impact
AMD CPUs since roughly 2014 carry extensions to x86 debugging that Xen exposed to guests without properly managing the associated MSR state across context switches. A guest can use debug facilities to observe or interfere with state belonging to another context - debug hardware is designed to see everything, which is precisely why leaking it across a VM boundary matters.
Who can reach it
From inside a guest VM on AMD hardware under Xen.
What to do
Fixed in Xen (XSA-444). Update the hypervisor and reboot the host.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.