Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity.
The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Amd64-microcode | Ubuntu | esm-infra/xenial | * |