[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions. Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service. 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state. 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
References
Link Resource
https://xenbits.xenproject.org/xsa/advisory-444.html Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: XEN

Published: 2024-01-05T16:34:10.958Z

Updated: 2024-01-05T16:34:10.958Z

Reserved: 2023-06-01T10:44:17.066Z


Link: CVE-2023-34327

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-05T17:15:08.683

Modified: 2024-01-11T15:56:46.760


Link: CVE-2023-34327

JSON object: View

cve-icon Redhat Information

No data.