Permissions, Privileges, and Access Controls in Xen - CVE-2023-46840

 

Permissions, Privileges, and Access Controls in Xen - CVE-2023-46840

Published: January 31, 2024


Vulnerability identifier: #VU85928
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2023-46840
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a malicious guest to bypass implemented security restrictions.

The vulnerability exists due to incorrect placement of a preprocessor directive in source code, which results in a logic error when support for HVM guests is compiled out of Xen and CONFIG_HVM is disabled at Xen's build time. When a device is removed from a domain, it is not properly quarantined and retains its access to the domain to which it was previously assigned. An attacker with control over a malicious guest can retain access to the domain after it has been removed from it.


Affected software

Xen
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
xen
xen-debugsource
xen-libs-64bit
xen-libs-64bit-debuginfo
xen-tools-xendomains-wait-disk
xen-doc-html
xen-tools
xen-tools-debuginfo
xen-libs-32bit
xen-libs-32bit-debuginfo
xen-tools-domU
xen-devel
xen-libs-debuginfo
xen-libs
xen-tools-domU-debuginfo
app-emulation/xen

How to mitigate CVE-2023-46840

Install updates from vendor's website.

xen - addressed in versions 4.17.2-6.fc38, 4.17.2-6.fc39
xen-debugsource - update to 4.17.3_04-150500.3.21.1
xen-libs-64bit - update to 4.17.3_04-150500.3.21.1
xen-libs-64bit-debuginfo - update to 4.17.3_04-150500.3.21.1
xen-tools-xendomains-wait-disk - update to 4.17.3_04-150500.3.21.1
xen-doc-html - update to 4.17.3_04-150500.3.21.1
xen-tools - update to 4.17.3_04-150500.3.21.1
xen - update to 4.17.3_04-150500.3.21.1
xen-tools-debuginfo - update to 4.17.3_04-150500.3.21.1
xen-libs-32bit - update to 4.17.3_04-150500.3.21.1
xen-libs-32bit-debuginfo - update to 4.17.3_04-150500.3.21.1
xen-tools-domU - update to 4.17.3_04-150500.3.21.1
xen-devel - update to 4.17.3_04-150500.3.21.1
xen-libs-debuginfo - update to 4.17.3_04-150500.3.21.1
xen-libs - update to 4.17.3_04-150500.3.21.1
xen-tools-domU-debuginfo - update to 4.17.3_04-150500.3.21.1
app-emulation/xen - update to 4.17.4

External References

Related Security Bulletins