Permissions, Privileges, and Access Controls in Xen - CVE-2023-46835
Published: November 15, 2023
Xen
Detailed vulnerability description
The vulnerability allows a remote guest to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions caused by a mismatch in IOMMU quarantine page table levels. A device in quarantine mode can access data from previous quarantine page table usages, possibly leaking data used by previous domains that also had the device assigned.