Database/Firmware, BMC & network fabric

Linux KVM - SEV-ES/SEV-SNP VMGEXIT double-fetch race: A KVM guest running SEV-ES or SEV-SNP with several vCPUs can
Impact
A KVM guest running SEV-ES or SEV-SNP with several vCPUs can trigger a double-fetch race in the host's VMGEXIT handler and drive it into recursion. Repeated invocation exhausts the host kernel stack and panics the hypervisor - a confidential guest taking down the host it runs on, and with it every other tenant on that machine. This is guest-to-host denial of service, which is the direction operators care about.
Who can reach it
From inside a guest VM using SEV-ES or SEV-SNP with multiple vCPUs. Tenant-reachable - no host privilege needed.
What to do
Fixed in the Linux kernel - KVM/x86 SEV code or the ccp/PSP driver. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and **reboot the host**; SEV/SNP hypervisor paths cannot be live-patched in any meaningful way, and SNP platform init/shutdown is not safe to cycle under running guests. Drain confidential-VM tenants, reboot, then re-admit. No firmware, VBIOS or AGESA step needed, which makes this one of the cheaper classes of SEV fix to roll out. Prioritise on any host that admits tenant-controlled confidential VMs; the attacker prerequisite is just 'has a VM here'.
References
Related entries
- GRUB2 (NTFS filesystem parser): Out-of-bounds read in the same NTFS path leaks GRUB heap memoryCVE-2023-4693 · GRUB2 (NTFS filesystem parser)Medium
- Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPS: Path traversal letsCVE-2023-6032 · Schneider Electric Galaxy VS / VL / VXL three-phase UPS, Network Management Card over HTTPSMedium
- Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race): A time-of-check/time-of-use race in BIOS givesCVE-2024-0171 · Dell PowerEdge Server BIOS (AMD platforms, TOCTOU race)Medium
- Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is notCVE-2024-27891 · Arista EOS (MACsec with egress ACLs)Medium
- Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privilegedCVE-2024-31157 · Intel UEFI firmware (OutOfBandXML module)Medium
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationCVE-2024-38303 · Dell PowerEdge 14G Intel BIOS (improper input validation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.