[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions. Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service. 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state. 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
References
Link Resource
https://xenbits.xenproject.org/xsa/advisory-444.html Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: XEN

Published: 2024-01-05T16:34:11.100Z

Updated: 2024-01-05T16:34:11.100Z

Reserved: 2023-06-01T10:44:17.066Z


Link: CVE-2023-34328

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-05T17:15:08.730

Modified: 2024-01-11T15:56:17.957


Link: CVE-2023-34328

JSON object: View

cve-icon Redhat Information

No data.