CVE-2023-46839

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/03/2024
Last modified:
13/01/2026

Description

PCI devices can make use of a functionality called phantom functions,<br /> that when enabled allows the device to generate requests using the IDs<br /> of functions that are otherwise unpopulated. This allows a device to<br /> extend the number of outstanding requests.<br /> <br /> Such phantom functions need an IOMMU context setup, but failure to<br /> setup the context is not fatal when the device is assigned. Not<br /> failing device assignment when such failure happens can lead to the<br /> primary device being assigned to a guest, while some of the phantom<br /> functions are assigned to a different domain.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*