[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

AMD CPUs since ~2014 have extensions to normal x86 debugging functionality.
Xen supports guests using these extensions.

Unfortunately there are errors in Xen's handling of the guest state, leading
to denials of service.

1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of
a previous vCPUs debug mask state.

2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT.
This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock
up the CPU entirely.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-38409 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal x86 debugging functionality. Xen supports guests using these extensions. Unfortunately there are errors in Xen's handling of the guest state, leading to denials of service. 1) CVE-2023-34327 - An HVM vCPU can end up operating in the context of a previous vCPUs debug mask state. 2) CVE-2023-34328 - A PV vCPU can place a breakpoint over the live GDT. This allows the PV vCPU to exploit XSA-156 / CVE-2015-8104 and lock up the CPU entirely.
Fixes

Solution

No solution given by the vendor.


Workaround

For CVE-2023-34327, HVM VMs which can see the DBEXT feature are not susceptible to running in the wrong state. By default, VMs will see the DBEXT feature on capable hardware, and when not explicitly levelled for migration compatibility. For CVE-2023-34328, PV VMs which cannot see the DBEXT feature cannot leverage the vulnerability.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: XEN

Published:

Updated: 2025-06-03T14:41:06.224Z

Reserved: 2023-06-01T10:44:17.066Z

Link: CVE-2023-34328

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-01-05T17:15:08.730

Modified: 2025-06-03T15:15:34.270

Link: CVE-2023-34328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.