CVE-2023-20592
published 2023-11-14CVE-2023-20592: Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.02%
59.4th percentile
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 1st_gen_amd_epyc_processors | — | — |
| amd | 2nd_gen_amd_epyc_processors | — | — |
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | epyc_7203_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7203p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_72f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7303_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7303p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7343_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7373x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_73f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7413_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7453_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7473x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_74f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7513_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7573x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_75f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7643_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-20592: Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-
osv·2023-11-14·CVSS 6.5
CVE-2023-20592 [MEDIUM] CVE-2023-20592: Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
GHSA
GHSA-5prp-6h6f-f55f: Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-
ghsa_unreviewed·2023-11-14
CVE-2023-20592 [MEDIUM] GHSA-5prp-6h6f-f55f: Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
Red Hat
hw: amd: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem
vendor_redhat·2023-11-14·CVSS 6.5
CVE-2023-20592 [MEDIUM] CWE-221 hw: amd: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem
hw: amd: INVD instruction may lead to a loss of SEV-ES guest machine memory integrity problem
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
A flaw was found in some of AMD CPU's due to improper or unexpected behavior of the INVD. This issue may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU, potentially leading to a loss of guest virtual machine (VM) memory integrity.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use a
Debian
CVE-2023-20592: amd64-microcode - Improper or unexpected behavior of the INVD instruction in some AMD CPUs may all...
vendor_debian·2023·CVSS 6.5
CVE-2023-20592 [MEDIUM] CVE-2023-20592: amd64-microcode - Improper or unexpected behavior of the INVD instruction in some AMD CPUs may all...
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
Scope: local
bookworm: resolved (fixed in 3.20230719.1~deb12u1)
bullseye: resolved (fixed in 3.20230719.1~deb11u1)
forky: resolved (fixed in 3.20230719.1)
sid: resolved (fixed in 3.20230719.1)
trixie: resolved (fixed in 3.20230719.1)
No detection rules found.
No public exploits indexed.
Talos
We all just need to agree that ad blockers are good
blogs_talos·2023-11-16
We all just need to agree that ad blockers are good
## We all just need to agree that ad blockers are good
I don’t think this is a particularly bold take — but I’m not afraid to say that ad blockers are good!
Ever since I started using one sometime in 2016, my experience of using the internet has improved exponentially. I can finally easily find a recipe for dinner on a random influencer’s blog, get a faster answer to “how to replace my car’s headlights” and likely avoid hundreds of pieces of malvertising .
But their use has increasingly come into question with YouTube’s new policies on preventing users from using ad blockers on its site, with new warnings saying the user has a certain number of videos they can watch before they must allowlist youtube.com in their ad blocker, thus allowing the site to display ads before YouTube videos.
Talos
We all just need to agree that ad blockers are good
blogs_talos·2023-11-16
We all just need to agree that ad blockers are good
I don’t think this is a particularly bold take — but I’m not afraid to say that ad blockers are good!
Ever since I started using one sometime in 2016, my experience of using the internet has improved exponentially. I can finally easily find a recipe for dinner on a random influencer’s blog, get a faster answer to “how to replace my car’s headlights” and likely avoid hundreds of pieces of malvertising.
But their use has increasingly come into question with YouTube’s new policies on preventing users from using ad blockers on its site, with new warnings saying the user has a certain number of videos they can watch before they must allowlist youtube.com in their ad blocker, thus allowing the site to display ads before YouTube videos.
The second this popped up for me two weeks ago, I immedia
Bleepingcomputer
New CacheWarp AMD CPU attack lets hackers gain root in Linux VMs
blogs_bleepingcomputer·2023-11-14·CVSS 6.5
[MEDIUM] New CacheWarp AMD CPU attack lets hackers gain root in Linux VMs
## New CacheWarp AMD CPU attack lets hackers gain root in Linux VMs
## Sergiu Gatlan
A new software-based fault injection attack, CacheWarp, can let threat actors hack into AMD SEV-protected virtual machines by targeting memory writes to escalate privileges and gain remote code execution.
This new attack exploits flaws in AMD's Secure Encrypted Virtualization-Encrypted State (SEV-ES) and Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP) tech designed to protect against malicious hypervisors and reduce the attack surface of VMs by encrypting VM data and blocking attempts to alter it in any way.
The underlying vulnerability (CVE-2023-20592) was discovered by security researchers with CISPA Helmholtz Center for Information Security and Graz University of Technology and indepe
2023-11-14
Published