Описание
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.
A flaw was found in the microcode that manages NBIO registers. A local attacker with administrative privileges could exploit a missing security control, allowing them to alter critical system configurations. This could compromise the integrity of virtual machines protected by Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP), potentially leading to unauthorized data tampering or execution within the guest.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | microcode_ctl | Out of support scope | ||
| Red Hat Enterprise Linux 8 | microcode_ctl | Fix deferred | ||
| Red Hat Enterprise Linux 9 | microcode_ctl | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6 Medium
CVSS3
Связанные уязвимости
Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.
EPSS
6 Medium
CVSS3