{"schema_version":"1.7.5","id":"CVE-2024-31146","published":"2024-09-25T11:15:12Z","modified":"2026-04-16T04:35:55.982513916Z","related":["SUSE-SU-2024:2994-1","SUSE-SU-2024:3001-1","SUSE-SU-2024:3010-1","SUSE-SU-2024:3075-1","SUSE-SU-2024:3113-1","SUSE-SU-2024:3423-1","SUSE-SU-2024:3586-1","openSUSE-SU-2024:14283-1"],"details":"When multiple devices share resources and one of them is to be passed\nthrough to a guest, security of the entire system and of respective\nguests individually cannot really be guaranteed without knowing\ninternals of any of the involved guests.  Therefore such a configuration\ncannot really be security-supported, yet making that explicit was so far\nmissing.\n\nResources the sharing of which is known to be problematic include, but\nare not limited to\n- - PCI Base Address Registers (BARs) of multiple devices mapping to the\n  same page (4k on x86),\n- - INTx lines.","references":[{"type":"ADVISORY","url":"https://xenbits.xenproject.org/xsa/advisory-461.html"},{"type":"ADVISORY","url":"http://xenbits.xen.org/xsa/advisory-461.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/08/14/3"}]}