Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci/hisilicon): The VFIO migration driver reassembled the device's event-queue DMA addresses
Impact
The VFIO migration driver reassembled the device's event-queue DMA addresses from hardware registers in the wrong byte order, so after a live migration the accelerator was programmed to DMA at addresses that were never the ones the guest set up. The device ends up writing to the wrong place inside the assigned domain and the guest's crypto services fail; the same class of mistake in an address-composition path is what turns a migration into a stray-DMA event, and the fix has to carry a magic-number check because guests migrated from old kernels otherwise land on bad addresses silently.
Who can reach it
Not attacker-initiated: triggered by live-migrating a guest that has a HiSilicon accelerator VF assigned under hisi_acc_vfio_pci, including migrations from an older kernel to a newer one. The resulting DMA is still bounded by the guest's IOMMU domain, so this is corruption and device malfunction inside the tenant rather than a host escape. Conditional on hisi_acc_vfio_pci being bound and live migration being in use - not reachable on an NVIDIA/AMD GPU fleet that never loads this driver.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel on nodes using hisi_acc_vfio_pci, and patch source and destination hosts together so the migration magic-number handling matches. Interim: disable live migration for HiSilicon accelerator VFs.
References
Related entries
- Linux kernel (drivers/vfio/pci/hisilicon): The guest decides whether the host's VFIO migration code has a valid queueCVE-2025-38283 · Linux kernel (drivers/vfio/pci/hisilicon)High
- Linux kernel (drivers/vfio/pci/hisilicon): The VFIO migration save and resume paths do not advance the data pointer byCVE-2023-52453 · Linux kernel (drivers/vfio/pci/hisilicon)High
- Linux KVM - CPU soft lockup setting per-page memory attributes on large SNP guests: Running an SEV-SNP guestCVE-2025-38506 · Linux KVM - CPU soft lockup setting per-page memory attributes on large SNP guestsMedium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedCVE-2025-38520 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel BPF verifier: narrow read of a pointer context field triggers a verifier bug warningCVE-2025-38591 · Linux kernel BPF verifier (narrow access to pointer context fields)Medium
- Linux kernel (drivers/pci/hotplug): A surprise device removal freezes the PCI host bridge's partitionable endpoint andCVE-2025-38623 · Linux kernel (drivers/pci/hotplug)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.