pci: phantom functions assigned to incorrect contexts
Published Mar 20, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.80%
Description
PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend the number of outstanding requests.
Such phantom functions need an IOMMU context setup, but failure to setup the context is not fatal when the device is assigned. Not failing device assignment when such failure happens can lead to the primary device being assigned to a guest, while some of the phantom functions are assigned to a different domain.
Affected products
No data.
Configuration 2
- 39
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
There is no mitigation (other than not passing through PCI devices with phantom functions to guests).
Red Hat statement
This vulnerability doesn't affect any supported Red Hat product.
No CWE recorded.
References (8)
- http://xenbits.xen.org/xsa/advisory-449.html PatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-46839 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2270533 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-51005 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XLL6SQ6IKFYXLYWITYZCRV5IBRK5G35R/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-46839
- https://www.cve.org/CVERecord?id=CVE-2023-46839
- https://xenbits.xenproject.org/xsa/advisory-449.html PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://xenbits.xen.org/xsa/advisory-449.html | PatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-46839 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2270533 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-51005 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XLL6SQ6IKFYXLYWITYZCRV5IBRK5G35R/ | Mailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-46839 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-46839 | ||
| https://xenbits.xenproject.org/xsa/advisory-449.html | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data