Back

MEDIUM

pci: phantom functions assigned to incorrect contexts

Published Mar 20, 2024

Description

PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend the number of outstanding requests.

Such phantom functions need an IOMMU context setup, but failure to setup the context is not fatal when the device is assigned. Not failing device assignment when such failure happens can lead to the primary device being assigned to a guest, while some of the phantom functions are assigned to a different domain.

Affected products

Remediation

Vendor solution

There is no mitigation (other than not passing through PCI devices with phantom functions to guests).

Red Hat statement

This vulnerability doesn't affect any supported Red Hat product.

Weaknesses (0)

No CWE recorded.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner XEN
Published Mar 20, 2024
Updated Nov 4, 2025
Reserved Oct 27, 2023

CISA Vulnrichment

Updated Aug 6, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 20, 2024
Bugzilla 2270533

ENISA EUVD

Assigner XEN
Published Mar 20, 2024
Updated Nov 4, 2025

GitHub

No data