GPU VulnDB

Database/NVIDIA / GPU stack

Linux drm/virtio: virtio-gpu hands guest-physical addresses to the host on Xen PV, exposing another domain's memory

CVSS 7.8CVE-2026-98156NVIDIA / GPU stackcurated

Impact

virtio-gpu decided whether to use the DMA API from the VIRTIO_F_ACCESS_PLATFORM feature bit alone, ignoring the Xen case that virtio_ring already handles. In a Xen PV domain, guest-physical addresses bear no relation to machine addresses, so the framebuffer backing pages described to the host resolve to pages belonging to some other domain and the host scans out unrelated memory. That is a cross-domain memory disclosure through the display path, plus corruption risk, and it also restores the dma_sync calls needed for correctness when swiotlb is in play. The practical exposure for a GPU fleet is narrow: it needs Xen PV (not PVH, which is identity-mapped) with virtio-vga, a configuration most accelerator hosts do not run. Where it does apply, no attacker action is required for the leak - it is a property of the configuration.

Who can reach it

No remote or authenticated attack step: a Xen PV domain running the virtio-gpu driver against a host that did not negotiate VIRTIO_F_ACCESS_PLATFORM (QEMU's virtio-vga default) causes the host to read pages of other domains. A local user in the guest able to drive the display path widens what gets referenced. PVH and HVM domains are not affected.

What to do

Take the stable kernel update containing the fix (three stable commits are linked; pick the one for your series) and reboot each affected host or guest - a kernel change on the DRM path cannot be hot-patched. If you cannot reboot soon, the configuration-level mitigation is to stop using Xen PV domains with virtio-vga: PVH dom0 is unaffected, and enabling iommu_platform on the virtio-vga device makes virtio-gpu take the DMA API path on its own.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.