CVE-2024-31145

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
25/09/2024
Last modified:
26/09/2024

Description

Certain PCI devices in a system might be assigned Reserved Memory<br /> Regions (specified via Reserved Memory Region Reporting, "RMRR") for<br /> Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used<br /> for platform tasks such as legacy USB emulation.<br /> <br /> Since the precise purpose of these regions is unknown, once a device<br /> associated with such a region is active, the mappings of these regions<br /> need to remain continuouly accessible by the device. In the logic<br /> establishing these mappings, error handling was flawed, resulting in<br /> such mappings to potentially remain in place when they should have been<br /> removed again. Respective guests would then gain access to memory<br /> regions which they aren&amp;#39;t supposed to have access to.

References to Advisories, Solutions, and Tools