Database/Control plane, storage & DevOps
Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code): On 64-bit platforms the pfn_to_kaddr() macro
Impact
On 64-bit platforms the pfn_to_kaddr() macro dropped high address bits when handed a narrower type, producing wrong kernel addresses in the SEV-SNP support paths that use it. Wrong addresses in code that manages confidential-guest page state means operating on memory that is not the memory intended - a correctness failure right underneath the mechanism enforcing guest isolation.
Who can reach it
Local, in the host kernel's SNP page-management paths.
What to do
Fixed in the Linux kernel - KVM/x86 SEV code or the ccp/PSP driver. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and **reboot the host**; SEV/SNP hypervisor paths cannot be live-patched in any meaningful way, and SNP platform init/shutdown is not safe to cycle under running guests. Drain confidential-VM tenants, reboot, then re-admit. No firmware, VBIOS or AGESA step needed, which makes this one of the cheaper classes of SEV fix to roll out.
References
Related entries
- Linux perf/x86/amd/core - overflow status not cleared for unhandled indices: Unhandled overflow bits are left setCVE-2023-53073 · Linux perf/x86/amd/core - overflow status not cleared for unhandled indicesMedium
- Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errors: On AMD Zen systems, the InstructionCVE-2023-53438 · Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errorsMedium
- Linux i915 GVT-g mediated GPU virtualisation: Unsafe cleanup of per-vGPU debugfs state when a mediated vGPU isCVE-2023-53625 · Linux i915 GVT-g mediated GPU virtualisationMedium
- Citrix NetScaler ADC/Gateway: Code injection on the management interfaceCVE-2023-6548 · Citrix NetScaler ADC/GatewayMedium
- Linux nfsd (NFS server): Broken RELEASE_LOCKOWNER handling in nfsd causing state corruptionCVE-2024-26629 · Linux nfsd (NFS server)Medium
- Intel Neural Compressor: Input-validation failure reachable by an authenticated user, ending in privilege escalationCVE-2024-36284 · Intel Neural CompressorMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.