Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-31346

Опубликовано: 19 дек. 2023
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

A flaw was found in some AMD CPUs where the guest message responses have not been zero-initialized. This issue may allow a local attacker with the ability to run arbitrary code on a container or virtual machine to discover sensitive information contained in the host system's memory.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6linux-firmwareAffected
Red Hat Enterprise Linux 7linux-firmwareAffected
Red Hat Enterprise Linux 8linux-firmwareFixedRHSA-2024:426202.07.2024
Red Hat Enterprise Linux 8.2 Advanced Update Supportlinux-firmwareFixedRHSA-2024:588327.08.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlinux-firmwareFixedRHSA-2024:473323.07.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicelinux-firmwareFixedRHSA-2024:473323.07.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionslinux-firmwareFixedRHSA-2024:473323.07.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportlinux-firmwareFixedRHSA-2024:440909.07.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicelinux-firmwareFixedRHSA-2024:440909.07.2024
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionslinux-firmwareFixedRHSA-2024:440909.07.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2250458kernel: Reserved fields in guest message responses may not be zero initialized

EPSS

Процентиль: 9%
0.00035
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
больше 1 года назад

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

CVSS3: 6
nvd
больше 1 года назад

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

rocky
около 1 месяца назад

Moderate: linux-firmware security update

CVSS3: 6
github
больше 1 года назад

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

EPSS

Процентиль: 9%
0.00035
Низкий

4.4 Medium

CVSS3