PT-2023-7266 · Xen+2 · Xen+2

Roger Pau

+1

·

Published

2023-11-14

·

Updated

2025-06-17

·

CVE-2023-46835

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xen (affected versions not specified)
Description The issue arises from a mismatch in the IOMMU quarantine page table levels. On systems with no RAM above the 512GB mark, only 3 page-table levels are configured in the IOMMU, while the quarantine domain is initialized with 4 page table levels. This results in a device in quarantine mode gaining write access to the page destined to be a PDE, potentially leading to data leaks. The sink page the device gets read/write access to is no longer cleared between device assignment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-08294
CVE-2023-46835
OPENSUSE-SU-2023_4466-1
OPENSUSE-SU-2023_4475-1
OPENSUSE-SU-2023_4476-1
OPENSUSE-SU-2024:13442-1
SUSE-SU-2023:4466-1
SUSE-SU-2023:4475-1
SUSE-SU-2023:4476-1
SUSE-SU-2023:4484-1
SUSE-SU-2023:4485-1
SUSE-SU-2023:4486-1
SUSE-SU-2023:4945-1
SUSE-SU-2023_4466-1
SUSE-SU-2023_4484-1
SUSE-SU-2023_4485-1
SUSE-SU-2023_4486-1
SUSE-SU-2023_4945-1

Affected Products

Debian
Suse
Xen