
Linux drm/virtio: virtio-gpu hands guest-physical addresses to the host on Xen PV, exposing another domain's memory
Impact
virtio-gpu decided whether to use the DMA API from the VIRTIO_F_ACCESS_PLATFORM feature bit alone, ignoring the Xen case that virtio_ring already handles. In a Xen PV domain, guest-physical addresses bear no relation to machine addresses, so the framebuffer backing pages described to the host resolve to pages belonging to some other domain and the host scans out unrelated memory. That is a cross-domain memory disclosure through the display path, plus corruption risk, and it also restores the dma_sync calls needed for correctness when swiotlb is in play. The practical exposure for a GPU fleet is narrow: it needs Xen PV (not PVH, which is identity-mapped) with virtio-vga, a configuration most accelerator hosts do not run. Where it does apply, no attacker action is required for the leak - it is a property of the configuration.
Who can reach it
No remote or authenticated attack step: a Xen PV domain running the virtio-gpu driver against a host that did not negotiate VIRTIO_F_ACCESS_PLATFORM (QEMU's virtio-vga default) causes the host to read pages of other domains. A local user in the guest able to drive the display path widens what gets referenced. PVH and HVM domains are not affected.
What to do
Take the stable kernel update containing the fix (three stable commits are linked; pick the one for your series) and reboot each affected host or guest - a kernel change on the DRM path cannot be hot-patched. If you cannot reboot soon, the configuration-level mitigation is to stop using Xen PV domains with virtio-vga: PVH dom0 is unaffected, and enabling iommu_platform on the virtio-vga device makes virtio-gpu take the DMA API path on its own.
References
Related entries
- NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko): An out-of-bounds readCVE-2022-28183 · NVIDIA GPU Display Driver - kernel mode layer (Windows nvlddmkm.sys and Linux nvidia.ko)High
- DGX servers BMC: Improper access control on BMCCVE-2022-42275 · DGX servers BMCHigh
- KAI Scheduler: Missing authentication on API endpointsCVE-2026-24177 · KAI SchedulerHigh
- NVIDIA Windows GPU driver: out-of-bounds read with no privileges required, leaking data and crashing the driverCVE-2026-47576 · NVIDIA GPU Display Driver for Windows (kernel module)High
- Linux amdgpu: unbounded FRU PIA TLV walk reads out of bounds on malformed EEPROM dataCVE-2026-97428 · Linux kernel drm/amdgpu (FRU EEPROM PIA/TLV parser)High
- DGX H100 BMC (IPMI): Credential exposureCVE-2023-25531 · DGX H100 BMC (IPMI)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.