CVE Vulnerabilities

CVE-2023-31356

Incomplete Cleanup

Published: Aug 13, 2024 | Modified: Feb 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.4 MODERATE
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 8RedHatlinux-firmware-0:20240827-124.git3cff7109.el8_10*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatlinux-firmware-0:20240827-114.3.git3cff7109.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatlinux-firmware-0:20240827-114.3.git3cff7109.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatlinux-firmware-0:20240827-114.3.git3cff7109.el8_6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatlinux-firmware-0:20240827-118.3.git3cff7109.el8_8*
Red Hat Enterprise Linux 9RedHatlinux-firmware-0:20240905-143.3.el9_4*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatlinux-firmware-0:20240905-138.3.el9_2*
Amd64-microcodeUbuntunoble*
Amd64-microcodeUbuntuoracular*
Amd64-microcodeUbuntutrusty/esm*
Amd64-microcodeUbuntuupstream*

Potential Mitigations

References