Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-20592

Опубликовано: 14 нояб. 2023
Источник: debian
EPSS Низкий

Описание

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
amd64-microcodefixed3.20230719.1package
amd64-microcodefixed3.20230719.1~deb12u1bookwormpackage
amd64-microcodefixed3.20230719.1~deb11u1bullseyepackage
amd64-microcodefixed3.20230719.1~deb10u1busterpackage

Примечания

  • https://cachewarpattack.com/

  • https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3005.html

EPSS

Процентиль: 57%
0.0036
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVSS3: 5.3
redhat
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVSS3: 6.5
nvd
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVSS3: 6.5
github
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость реализации процессорной инструкции INVD для виртуальных машин, работающих на серверах с процессорами AMD, позволяющая нарушителю привести к потере целостности памяти гостевой виртуальной машины

EPSS

Процентиль: 57%
0.0036
Низкий