Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2023-46840
NixOS vulnerability analysis and mitigation

Overview

CVE-2023-46840 is a vulnerability in Xen's VT-d functionality discovered by Teddy Astie of Vates. The issue stems from incorrect placement of a preprocessor directive in source code that affects logic when support for HVM guests is compiled out of Xen. This vulnerability affects Xen versions 4.17 and onwards, specifically on x86 platforms with Intel-compatible VT-d IOMMU, when CONFIG_HVM is disabled at build time (Xen Advisory).

Technical details

The vulnerability occurs due to improper preprocessing directive placement in the source code, which causes unintended behavior when HVM guest support is compiled out. This specifically affects the VT-d (Intel's Virtualization Technology for Directed I/O) functionality in Xen. The issue is only present when CONFIG_HVM is disabled during build time, though most deployments typically have this enabled by default (Xen Advisory).

Impact

When a device is removed from a domain, it is not properly quarantined and retains its access to the domain to which it was previously assigned. This impact is particularly relevant for systems where PCI devices are passed through to untrusted or semi-trusted guests (Xen Advisory).

Exploitability

The vulnerability affects systems running Xen 4.17 and later versions on x86 platforms with Intel-compatible VT-d IOMMU. Systems are only vulnerable when CONFIG_HVM is disabled at build time and when PCI devices are passed through to untrusted or semi-trusted guests. Systems that do not assign PCI devices to untrusted guests are not vulnerable (Xen Advisory).

Mitigation and workarounds

There is no mitigation available for this vulnerability. The only resolution is to apply the security patch provided in the advisory. The patch has been prepared to apply to stable branches, and downstream users are encouraged to update to the tip of the stable branch before applying these patches (Xen Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Alpine

Fixed

edge

xen: 0

Fixed

v3.18

xen: 0

Fixed

v3.19

xen: 0

Fixed

v3.20

xen: 0

Fixed

v3.21

xen: 0

Fixed

v3.22

xen: 0

Fixed

v3.23

xen: 0

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • seal-binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management