CVE-2023-20573
published 2024-01-11CVE-2023-20573: A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.
PriorityP48low3.2CVSS 3.1
AVLACLPRHUINSCCNILAN
EPSS
0.29%
20.7th percentile
A privileged attacker
can prevent delivery of debug exceptions to SEV-SNP guests potentially
resulting in guests not receiving expected debug information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | 4th_gen_amd_epyc_processors | — | — |
CVSS provenance
nvdv3.13.2LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: hw: AMD Secure Nested Paging Debug Exception
vendor_redhat·2024-01-09·CVSS 3.2
CVE-2023-20573 [LOW] CWE-1301 kernel: hw: AMD Secure Nested Paging Debug Exception
kernel: hw: AMD Secure Nested Paging Debug Exception
A privileged attacker
can prevent delivery of debug exceptions to SEV-SNP guests potentially
resulting in guests not receiving expected debug information.
A flaw was found in AMD hardware using the Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP) feature. This issue may allow a privileged attacker to prevent the delivery of debug exceptions to SEV-SNP guests, potentially resulting in guests not receiving expected debug information.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel (Red Hat Virtualization 4) - Not
GHSA
GHSA-6hrc-q74x-c8g8: A privileged attacker
can prevent delivery of debug exceptions to SEV-SNP guests potentially
resulting in guests not receiving expected debug informat
ghsa_unreviewed·2024-01-11
CVE-2023-20573 [LOW] CWE-693 GHSA-6hrc-q74x-c8g8: A privileged attacker
can prevent delivery of debug exceptions to SEV-SNP guests potentially
resulting in guests not receiving expected debug informat
A privileged attacker
can prevent delivery of debug exceptions to SEV-SNP guests potentially
resulting in guests not receiving expected debug information.
No detection rules found.
No public exploits indexed.
2024-01-11
Published