Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-31315

Опубликовано: 12 авг. 2024
Источник: debian

Описание

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
amd64-microcodefixed3.20240710.1package
amd64-microcodefixed3.20240710.2~deb12u1bookwormpackage
amd64-microcodefixed3.20240710.2~deb11u1bullseyepackage

Примечания

  • https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

CVSS3: 7.5
redhat
10 месяцев назад

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

CVSS3: 7.5
nvd
10 месяцев назад

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

suse-cvrf
7 месяцев назад

Security update for kernel-firmware

suse-cvrf
10 месяцев назад

Security update for kernel-firmware