Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-34326
HistoryJan 05, 2024 - 12:00 a.m.

CVE-2023-34326

2024-01-0500:00:00
ubuntu.com
ubuntu.com
18
caching guidelines
amd-vi
hardware malfunction
stale dma mappings
iommu tlb
memory regions

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

9.0%

The caching invalidation guidelines from the AMD-Vi specification
(48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices
will malfunction (see stale DMA mappings) if some fields of the DTE are
updated but the IOMMU TLB is not flushed. Such stale DMA mappings can point
to memory ranges not owned by the guest, thus allowing access to unindented
memory regions.

Notes

Author Note
mdeslaur hypervisor packages are in universe. For issues in the hypervisor, add appropriate tags to each section, ex: Tags_xen: universe-binary

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

9.0%