cbcvebase.
CVE-2023-34326
published 2024-01-05

CVE-2023-34326: The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
20.7th percentile
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see stale DMA mappings) if some fields of the DTE are updated but the IOMMU TLB is not flushed. Such stale DMA mappings can point to memory ranges not owned by the guest, thus allowing access to unindented memory regions.

Affected

15 ranges
VendorProductVersion rangeFixed in
citrixcitrix_hypervisor
citrixxenserver
debianxen< xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm)xen 4.17.2+76-ge1f9cb16e2-1~deb12u1 (bookworm)
xenxen>= 0 < 4.15.5-r34.15.5-r3
xenxen>= 0 < 4.16.5-r34.16.5-r3
xenxen>= 0 < 4.16.5-r34.16.5-r3
xenxen>= 0 < 4.17.2-r34.17.2-r3
xenxen>= 0 < 4.17.2-r34.17.2-r3
xenxen>= 0 < 4.17.2-r34.17.2-r3
xenxen>= 0 < 4.17.2-r34.17.2-r3
xenxen>= 0 < 4.17.2-r34.17.2-r3
xenxen>= 0 < 4.17.2-r34.17.2-r3
xenxen>= 0 < 4.17.2+76-ge1f9cb16e2-1~deb12u14.17.2+76-ge1f9cb16e2-1~deb12u1
xenxen>= 0 < 4.17.2+55-g0b56bed864-14.17.2+55-g0b56bed864-1
xenxen>= 0 < 4.17.2+55-g0b56bed864-14.17.2+55-g0b56bed864-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.