CVE Vulnerabilities

CVE-2023-20584

Published: Aug 13, 2024 | Modified: Dec 12, 2024
CVSS 3.x
6
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.

Affected Software

NameVendorStart VersionEnd Version
Epyc_8024pn_firmwareAmd*genoapi_1.0.0.b (excluding)
Red Hat Enterprise Linux 8RedHatlinux-firmware-0:20240827-124.git3cff7109.el8_10*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatlinux-firmware-0:20240827-114.3.git3cff7109.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatlinux-firmware-0:20240827-114.3.git3cff7109.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatlinux-firmware-0:20240827-114.3.git3cff7109.el8_6*
Red Hat Enterprise Linux 9RedHatlinux-firmware-0:20240905-143.3.el9_4*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatlinux-firmware-0:20240905-138.3.el9_2*
Amd64-microcodeUbuntunoble*
Amd64-microcodeUbuntuoracular*
Amd64-microcodeUbuntutrusty/esm*
Amd64-microcodeUbuntuupstream*

References