Database/Kernel, userspace & hypervisor
Intel DSA/IAA (idxd): Hardware erratum: direct access to Intel DSA/IAA accelerators by an untrusted application allows
CVSS 6.4CVE-2024-21823Kernel, userspace & hypervisorcurated
Impact
Hardware erratum: direct access to Intel DSA/IAA accelerators by an untrusted application allows privilege escalation
Who can reach it
Tenant process granted direct accelerator access; tenant VM guest with passthrough
What to do
Microcode + kernel driver update + reboot. Relevant wherever DSA/IAA is exposed to tenants alongside GPUs
References
Related entries
- Linux kernel (drivers/pci): Pm_runtime_get_sync() does not wait for an already-running .runtime_idle() callback, so aCVE-2024-35809 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci/hotplug): Powering off a physical function that still has child virtual functions drops theCVE-2025-37946 · Linux kernel (drivers/pci/hotplug)Medium
- systemd: Privilege escalation via the systemctl `less` pager when sudo-granted systemctl is availableCVE-2023-26604 · systemdMedium
- Linux kernel (net/sched SFQ): Missing limit validation in sch_sfq - out-of-bounds writeCVE-2025-37752 · Linux kernel (net/sched SFQ)Medium
- libssh SCP client: malicious server can write files outside the client's working directoryCVE-2026-0964 · libssh SCP client (server-supplied path handling)Medium
- Linux kernel (drivers/pci/hotplug): A power fault on a PCIe hotplug slot latches a sticky status bit that the hardirqCVE-2021-47617 · Linux kernel (drivers/pci/hotplug)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.