CVE-2023-46839
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/03/2024
Last modified:
13/01/2026
Description
PCI devices can make use of a functionality called phantom functions,<br />
that when enabled allows the device to generate requests using the IDs<br />
of functions that are otherwise unpopulated. This allows a device to<br />
extend the number of outstanding requests.<br />
<br />
Such phantom functions need an IOMMU context setup, but failure to<br />
setup the context is not fatal when the device is assigned. Not<br />
failing device assignment when such failure happens can lead to the<br />
primary device being assigned to a guest, while some of the phantom<br />
functions are assigned to a different domain.<br />
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* | ||
| cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



