CVE-2023-34326
published 2024-01-05CVE-2023-34326: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
20.7th percentile
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction
(see stale DMA mappings) if some fields of the DTE are updated but the IOMMU
TLB is not flushed.
Such stale DMA mappings can point to memory ranges not owned by the guest, thus
allowing access to unindented memory regions.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_hypervisor | — | — |
| citrix | xenserver | — | — |
| debian | xen | < xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm) | xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm) |
| xen | xen | >= 0 < 4.15.5-r3 | 4.15.5-r3 |
| xen | xen | >= 0 < 4.16.5-r3 | 4.16.5-r3 |
| xen | xen | >= 0 < 4.16.5-r3 | 4.16.5-r3 |
| xen | xen | >= 0 < 4.17.2-r3 | 4.17.2-r3 |
| xen | xen | >= 0 < 4.17.2-r3 | 4.17.2-r3 |
| xen | xen | >= 0 < 4.17.2-r3 | 4.17.2-r3 |
| xen | xen | >= 0 < 4.17.2-r3 | 4.17.2-r3 |
| xen | xen | >= 0 < 4.17.2-r3 | 4.17.2-r3 |
| xen | xen | >= 0 < 4.17.2-r3 | 4.17.2-r3 |
| xen | xen | >= 0 < 4.17.2+76-ge1f9cb16e2-1~deb12u1 | 4.17.2+76-ge1f9cb16e2-1~deb12u1 |
| xen | xen | >= 0 < 4.17.2+55-g0b56bed864-1 | 4.17.2+55-g0b56bed864-1 |
| xen | xen | >= 0 < 4.17.2+55-g0b56bed864-1 | 4.17.2+55-g0b56bed864-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Citrix Hypervisor Multiple Security Updates
vendor_citrix·2023-10-10·CVSS 7.8
CVE-2022-1304 [HIGH] Citrix Hypervisor Multiple Security Updates
Citrix Hypervisor Multiple Security Updates
of Problem Several issues have been discovered that affect Citrix Hypervisor 8.2 CU1 LTSR and may allow malicious privileged code in a guest VM to: i) Compromise an AMD-based host via a passed through PCI device: CVE-2023-34326 ii) Compromise the host when a specific administrative action is taken (see
CVE References: CVE-2022-1304, CVE-2023-20588, CVE-2023-34324, CVE-2023-34326, CVE-2023-34327
Affected Products: Citrix Hypervisor, XenServer
Severity: High
Remediation:
We have released hotfixes to address these issues. We recommend that affected customers install these hotfixes and follow the instructions in the linked articles as their update schedule permits. The hotfixes can be downloaded from the following locations: CTX575070 - https://su
Debian
CVE-2023-34326: xen - The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.0...
vendor_debian·2023·CVSS 7.8
CVE-2023-34326 [HIGH] CVE-2023-34326: xen - The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.0...
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see stale DMA mappings) if some fields of the DTE are updated but the IOMMU TLB is not flushed. Such stale DMA mappings can point to memory ranges not owned by the guest, thus allowing access to unindented memory regions.
Scope: local
bookworm: resolved (fixed in 4.17.2+76-ge1f9cb16e2-1~deb12u1)
bullseye: open
forky: resolved (fixed in 4.17.2+55-g0b56bed864-1)
sid: resolved (fixed in 4.17.2+55-g0b56bed864-1)
trixie: resolved (fixed in 4.17.2+55-g0b56bed864-1)
GHSA
GHSA-mjvw-frxx-6hm5: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3
ghsa_unreviewed·2024-01-05
CVE-2023-34326 [HIGH] CWE-672 GHSA-mjvw-frxx-6hm5: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction
(see stale DMA mappings) if some fields of the DTE are updated but the IOMMU
TLB is not flushed.
Such stale DMA mappings can point to memory ranges not owned by the guest, thus
allowing access to unindented memory regions.
OSV
CVE-2023-34326: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3
osv·2024-01-05·CVSS 7.8
CVE-2023-34326 [HIGH] CVE-2023-34326: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see stale DMA mappings) if some fields of the DTE are updated but the IOMMU TLB is not flushed. Such stale DMA mappings can point to memory ranges not owned by the guest, thus allowing access to unindented memory regions.
OSV
CVE-2023-34326: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3
osv·2024-01-05·CVSS 7.8
CVE-2023-34326 [HIGH] CVE-2023-34326: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction
(see stale DMA mappings) if some fields of the DTE are updated but the IOMMU
TLB is not flushed.
Such stale DMA mappings can point to memory ranges not owned by the guest, thus
allowing access to unindented memory regions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-01-05
Published