Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-20592

Опубликовано: 14 нояб. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

A flaw was found in some of AMD CPU's due to improper or unexpected behavior of the INVD. This issue may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU, potentially leading to a loss of guest virtual machine (VM) memory integrity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6linux-firmwareAffected
Red Hat Enterprise Linux 9linux-firmwareAffected
Red Hat Enterprise Linux 7linux-firmwareFixedRHSA-2024:075309.02.2024
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)linux-firmwareFixedRHSA-2024:097826.02.2024
Red Hat Enterprise Linux 7.7 Advanced Update Supportlinux-firmwareFixedRHSA-2024:097927.02.2024
Red Hat Enterprise Linux 8linux-firmwareFixedRHSA-2024:317822.05.2024
Red Hat Enterprise Linux 8.2 Advanced Update Supportlinux-firmwareFixedRHSA-2024:457516.07.2024
Red Hat Enterprise Linux 8.6 Extended Update Supportlinux-firmwareFixedRHSA-2024:111205.03.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-221
https://bugzilla.redhat.com/show_bug.cgi?id=2244590hw: amd: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem

EPSS

Процентиль: 57%
0.0036
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVSS3: 6.5
nvd
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVSS3: 6.5
debian
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CP ...

CVSS3: 6.5
github
больше 1 года назад

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость реализации процессорной инструкции INVD для виртуальных машин, работающих на серверах с процессорами AMD, позволяющая нарушителю привести к потере целостности памяти гостевой виртуальной машины

EPSS

Процентиль: 57%
0.0036
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2023-20592