IOMMU improperly handles certain special address
ranges with invalid device table entries (DTEs), which may allow an attacker
with privileges and a compromised Hypervisor to
induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a
loss of guest integrity.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat enterprise Linux
Redhat rhel Eus |
|
CPEs | cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 cpe:/o:redhat:rhel_eus:9.2 |
|
Vendors & Products |
Redhat enterprise Linux
Redhat rhel Eus |
Tue, 01 Oct 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat rhel Aus Redhat rhel E4s Redhat rhel Tus |
|
CPEs | cpe:/o:redhat:rhel_aus:8.6 cpe:/o:redhat:rhel_e4s:8.6 cpe:/o:redhat:rhel_tus:8.6 |
|
Vendors & Products |
Redhat
Redhat rhel Aus Redhat rhel E4s Redhat rhel Tus |
Fri, 16 Aug 2024 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | kernel: hw:amd:IOMMU improperly handles certain special address leading to a loss of guest integrity | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 13 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 Aug 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity. | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: AMD
Published: 2024-08-13T16:53:18.373Z
Updated: 2024-11-05T21:40:37.392Z
Reserved: 2022-10-27T18:53:39.759Z
Link: CVE-2023-20584
Vulnrichment
Updated: 2024-08-13T17:32:43.152Z
NVD
Status : Awaiting Analysis
Published: 2024-08-13T17:15:19.713
Modified: 2024-08-14T02:07:05.410
Link: CVE-2023-20584
Redhat