CVE-2023-34326 Vulnerability Details

  /     /     /  

CVE-2023-34326 Metadata Quick Info

CVE Published: 05/01/2024 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: XEN | Vendor: Xen | Product: Xen
Status : PUBLISHED

CVE-2023-34326 Description

The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see stale DMA mappings) if some fields of the DTE are updated but the IOMMU TLB is not flushed. Such stale DMA mappings can point to memory ranges not owned by the guest, thus allowing access to unindented memory regions.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name:
Source: Xen

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description: Privilege escalation, Denial of Service (DoS) affecting the entire host, and information leaks.


Source: NVD (National Vulnerability Database).