CVE-2024-31146
published 2024-09-25CVE-2024-31146: When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually…
PriorityP434high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
EPSS
0.24%
14.5th percentile
When multiple devices share resources and one of them is to be passed
through to a guest, security of the entire system and of respective
guests individually cannot really be guaranteed without knowing
internals of any of the involved guests. Therefore such a configuration
cannot really be security-supported, yet making that explicit was so far
missing.
Resources the sharing of which is known to be problematic include, but
are not limited to
- - PCI Base Address Registers (BARs) of multiple devices mapping to the
same page (4k on x86),
- - INTx lines.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.17.5+23-ga4e5191dc0-1 (bookworm) | xen 4.17.5+23-ga4e5191dc0-1 (bookworm) |
| xen | xen | >= 0 < 4.17.5+23-ga4e5191dc0-1 | 4.17.5+23-ga4e5191dc0-1 |
| xen | xen | >= 0 < 4.19.1-1 | 4.19.1-1 |
| xen | xen | >= 0 < 4.19.1-1 | 4.19.1-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hrw6-9556-27w2: When multiple devices share resources and one of them is to be passed
through to a guest, security of the entire system and of respective
guests indiv
ghsa_unreviewed·2024-09-25
CVE-2024-31146 [HIGH] CWE-400 GHSA-hrw6-9556-27w2: When multiple devices share resources and one of them is to be passed
through to a guest, security of the entire system and of respective
guests indiv
When multiple devices share resources and one of them is to be passed
through to a guest, security of the entire system and of respective
guests individually cannot really be guaranteed without knowing
internals of any of the involved guests. Therefore such a configuration
cannot really be security-supported, yet making that explicit was so far
missing.
Resources the sharing of which is known to be problematic include, but
are not limited to
- - PCI Base Address Registers (BARs) of multiple devices mapping to the
same page (4k on x86),
- - INTx lines.
OSV
CVE-2024-31146: When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests indiv
osv·2024-09-25·CVSS 7.5
CVE-2024-31146 [HIGH] CVE-2024-31146: When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests indiv
When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually cannot really be guaranteed without knowing internals of any of the involved guests. Therefore such a configuration cannot really be security-supported, yet making that explicit was so far missing. Resources the sharing of which is known to be problematic include, but are not limited to - - PCI Base Address Registers (BARs) of multiple devices mapping to the same page (4k on x86), - - INTx lines.
Debian
CVE-2024-31146: xen - When multiple devices share resources and one of them is to be passed through to...
vendor_debian·2024·CVSS 7.5
CVE-2024-31146 [HIGH] CVE-2024-31146: xen - When multiple devices share resources and one of them is to be passed through to...
When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually cannot really be guaranteed without knowing internals of any of the involved guests. Therefore such a configuration cannot really be security-supported, yet making that explicit was so far missing. Resources the sharing of which is known to be problematic include, but are not limited to - - PCI Base Address Registers (BARs) of multiple devices mapping to the same page (4k on x86), - - INTx lines.
Scope: local
bookworm: resolved (fixed in 4.17.5+23-ga4e5191dc0-1)
bullseye: open
forky: resolved (fixed in 4.19.1-1)
sid: resolved (fixed in 4.19.1-1)
trixie: resolved (fixed in 4.19.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-25
Published