CVE-2023-20593
published 2023-07-24CVE-2023-20593: An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
PriorityP431medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
5.79%
92.3th percentile
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 2nd_gen_amd_epyc_processors | — | — |
| amd | 3rd_gen_amd_ryzen_threadripper_processors_castle_peak_hedt | — | — |
| amd | amd_ryzen_4000_series_desktop_processors_with_radeon_graphics_renoir_am4 | — | — |
| amd | ryzen_3000_series_desktop_processors_matisse_am4 | — | — |
| amd | ryzen_4000_series_mobile_processors_with_radeon_graphics_renoir | — | — |
| amd | ryzen_5000_series_mobile_processors_with_radeon_graphics_lucienne | — | — |
| amd | ryzen_7020_series_processors_mendocino_ft6 | — | — |
| amd | ryzen_threadripper_pro_processors_castle_peak_ws_sp3 | — | — |
| debian | amd64-microcode | < amd64-microcode 3.20230719.1~deb12u1 (bookworm) | amd64-microcode 3.20230719.1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < amd64-microcode 3.20230719.1~deb12u1 (bookworm) | amd64-microcode 3.20230719.1~deb12u1 (bookworm) |
| chrome_chrome | — | — | |
| linux | linux_kernel | >= 0 < 5.10.179-3 | 5.10.179-3 |
| linux | linux_kernel | >= 0 < 6.1.38-2 | 6.1.38-2 |
| linux | linux_kernel | >= 0 < 6.4.4-2 | 6.4.4-2 |
| linux | linux_kernel | >= 0 < 6.4.4-2 | 6.4.4-2 |
| linux | linux_kernel | >= 0 < 5.4.0-159.176 | 5.4.0-159.176 |
| linux | linux_kernel | >= 0 < 5.15.0-82.91 | 5.15.0-82.91 |
| linux | linux_kernel | >= 0 < 4.4.0-248.282 | 4.4.0-248.282 |
| linux | linux_kernel | >= 0 < 4.15.0-216.227 | 4.15.0-216.227 |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-12-05·CVSS 5.5
CVE-2023-45871 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sens
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-20593
vendor_chrome·2023-10-06·CVSS 5.5
CVE-2023-20593 [MEDIUM] Long Term Support Channel Update for ChromeOS: CVE-2023-20593
Long Term Support Channel Update for ChromeOS
CVE-2023-20593
Ubuntu
Linux kernel (BlueField) vulnerabilities
vendor_ubuntu·2023-09-26·CVSS 6.5
CVE-2023-2002 [MEDIUM] Linux kernel (BlueField) vulnerabilities
Title: Linux kernel (BlueField) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did
not properly perform permissions checks when handling HCI sockets. A
physically proximate attacker could use this to cause a denial of service
(bluetooth communication). (CVE-2023-2002)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2023-09-19·CVSS 4.7
CVE-2023-3141 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD x86-64 processors with SMT enabled could
speculatively execute instructions using a return address from a sibling
thread. A local attacker could possibly use this to expose sensitive
information. (CVE-2022-27672)
William Zhao discovered that the Traffic Control (TC) subsystem in the
Linux kernel did not properly handle network packet retransmission in
certain situations. A local attacker could use this to cause a denial of
service (kernel deadlock). (CVE-2022-4269)
Jordy Zomer and Alexandra Sandulescu discovered that syscalls invoking the
do_prlimit() function in the Linux kernel did not properly handle
speculative execution barriers. A local attack
Ubuntu
Linux kernel (IBM) vulnerabilities
vendor_ubuntu·2023-09-11·CVSS 6.5
CVE-2023-21255 [MEDIUM] Linux kernel (IBM) vulnerabilities
Title: Linux kernel (IBM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did
not properly perform permissions checks when handling HCI sockets. A
physically proximate attacker could use this to cause a denial of service
(bluetooth communication). (CVE-2023-2002)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose
Ubuntu
Linux kernel (Azure)
vendor_ubuntu·2023-09-08·CVSS 5.5
CVE-2023-3611 [MEDIUM] Linux kernel (Azure)
Title: Linux kernel (Azure)
Summary: Several security issues were fixed in the Linux kernel.
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Zheng Zhang discovered that the device-mapper implementation in the Linux
kernel did not properly handle locking during table_clear() operations. A
local attacker could use this to cause a denial of service (kernel
deadlock). (CVE-2023-2269)
It was discovered that a use-after-free vulnerability existed in the HFS+
file system implementation in the Linux kernel. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-2985)
It was discovered
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities
vendor_ubuntu·2023-09-06·CVSS 6.5
CVE-2023-20593 [MEDIUM] Linux kernel (Raspberry Pi) vulnerabilities
Title: Linux kernel (Raspberry Pi) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-09-06·CVSS 5.5
CVE-2023-2985 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Zheng Zhang discovered that the device-mapper implementation in the Linux
kernel did not properly handle locking during table_clear() operations. A
local attacker could use this to cause a denial of service (kernel
deadlock). (CVE-2023-2269)
It was discovered that a use-after-free vulnerability existed in the HFS+
file system implementation in the Linux kernel. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-2985)
It was di
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-09-06·CVSS 6.5
CVE-2023-4015 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
deni
Ubuntu
Linux kernel (Oracle) vulnerabilities
vendor_ubuntu·2023-08-31·CVSS 6.5
CVE-2023-3776 [MEDIUM] Linux kernel (Oracle) vulnerabilities
Title: Linux kernel (Oracle) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
loc
Ubuntu
Linux kernel (GCP) vulnerabilities
vendor_ubuntu·2023-08-31·CVSS 6.5
CVE-2023-4015 [MEDIUM] Linux kernel (GCP) vulnerabilities
Title: Linux kernel (GCP) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2023-08-31·CVSS 5.5
CVE-2023-2124 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the netlink implementation in the Linux kernel did
not properly validate policies when parsing attributes in some situations.
An attacker could use this to cause a denial of service (infinite
recursion). (CVE-2020-36691)
Billy Jheng Bing Jhong discovered that the CIFS network file system
implementation in the Linux kernel did not properly validate arguments to
ioctl() in some situations. A local attacker could possibly use this to
cause a denial of service (system crash). (CVE-2022-0168)
It was discovered that the ext4 file system implementation in the Linux
kernel contained a use-after-free vulnerability. An attacker could use this
to construct a maliciou
Ubuntu
Linux kernel (GKE) vulnerabilities
vendor_ubuntu·2023-08-31·CVSS 6.5
CVE-2023-3611 [MEDIUM] Linux kernel (GKE) vulnerabilities
Title: Linux kernel (GKE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-08-31·CVSS 6.5
CVE-2023-3776 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
deni
Ubuntu
Linux kernel (Azure) vulnerabilities
vendor_ubuntu·2023-08-31·CVSS 6.5
CVE-2023-3777 [MEDIUM] Linux kernel (Azure) vulnerabilities
Title: Linux kernel (Azure) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
William Zhao discovered that the Traffic Control (TC) subsystem in the
Linux kernel did not properly handle network packet retransmission in
certain situations. A local attacker could use this to cause a denial of
service (kernel deadlock). (CVE-2022-4269)
It was discovered that the NTFS file system implementation in the Linux
kernel did not properly check buffer indexes in certain situations, leading
to an out-of-bounds read vulner
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-08-31·CVSS 6.5
CVE-2023-3609 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local attack
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-08-30·CVSS 6.5
CVE-2023-4015 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local attack
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-08-29·CVSS 6.5
CVE-2023-20593 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
deni
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-08-29·CVSS 6.5
CVE-2023-3611 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local attack
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2023-08-29·CVSS 6.5
CVE-2023-4015 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Kevin Rich discovered that the netfilter subsystem in the Linux kernel did
not properly handle table rules flush in certain circumstances. A local
attacker could possibly use this to cause a denial of service (system
cr
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2023-08-29·CVSS 6.5
CVE-2022-40982 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local attack
Ubuntu
AMD Microcode vulnerability
vendor_ubuntu·2023-07-25
CVE-2023-20593 AMD Microcode vulnerability
Title: AMD Microcode vulnerability
Summary: AMD processors may allow an attacker to expose sensitive information due to a
vector register speculative execution vulnerability.
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local attacker
could use this to expose sensitive information.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
hw: amd: Cross-Process Information Leak
vendor_redhat·2023-07-25·CVSS 5.5
CVE-2023-20593 [MEDIUM] CWE-1239 hw: amd: Cross-Process Information Leak
hw: amd: Cross-Process Information Leak
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
A flaw was found in hw, in “Zen 2” CPUs. This issue may allow an attacker to access sensitive information under specific microarchitectural circumstances.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2023-20593: amd64-microcode - An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may a...
vendor_debian·2023·CVSS 5.5
CVE-2023-20593 [MEDIUM] CVE-2023-20593: amd64-microcode - An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may a...
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
Scope: local
bookworm: resolved (fixed in 3.20230719.1~deb12u1)
bullseye: resolved (fixed in 3.20230719.1~deb11u1)
forky: resolved (fixed in 3.20230719.1)
sid: resolved (fixed in 3.20230719.1)
trixie: resolved (fixed in 3.20230719.1)
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2023-12-05·CVSS 5.5
CVE-2023-20593 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)
Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). (CVE-
OSV
linux-bluefield vulnerabilities
osv·2023-09-26·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-bluefield vulnerabilities
linux-bluefield vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did
not properly perform permissions checks when handling HCI sockets. A
physically proximate attacker could use this to cause a denial of service
(bluetooth communication). (CVE-2023-2002)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Zi Fan Tan discovered that the bin
OSV
linux-oem-6.0 vulnerabilities
osv·2023-09-19·CVSS 4.7
CVE-2022-27672 [MEDIUM] linux-oem-6.0 vulnerabilities
linux-oem-6.0 vulnerabilities
It was discovered that some AMD x86-64 processors with SMT enabled could
speculatively execute instructions using a return address from a sibling
thread. A local attacker could possibly use this to expose sensitive
information. (CVE-2022-27672)
William Zhao discovered that the Traffic Control (TC) subsystem in the
Linux kernel did not properly handle network packet retransmission in
certain situations. A local attacker could use this to cause a denial of
service (kernel deadlock). (CVE-2022-4269)
Jordy Zomer and Alexandra Sandulescu discovered that syscalls invoking the
do_prlimit() function in the Linux kernel did not properly handle
speculative execution barriers. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2023-0
OSV
linux-ibm, linux-ibm-5.4 vulnerabilities
osv·2023-09-11·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-ibm, linux-ibm-5.4 vulnerabilities
linux-ibm, linux-ibm-5.4 vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did
not properly perform permissions checks when handling HCI sockets. A
physically proximate attacker could use this to cause a denial of service
(bluetooth communication). (CVE-2023-2002)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Zi Fan Tan discovered tha
OSV
linux-azure, linux-azure-4.15 vulnerabilities
osv·2023-09-08·CVSS 5.5
CVE-2023-20593 [MEDIUM] linux-azure, linux-azure-4.15 vulnerabilities
linux-azure, linux-azure-4.15 vulnerabilities
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Zheng Zhang discovered that the device-mapper implementation in the Linux
kernel did not properly handle locking during table_clear() operations. A
local attacker could use this to cause a denial of service (kernel
deadlock). (CVE-2023-2269)
It was discovered that a use-after-free vulnerability existed in the HFS+
file system implementation in the Linux kernel. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-2985)
It was discovered that the DVB Core driver in the Linux kernel di
OSV
linux-raspi, linux-raspi-5.4 vulnerabilities
osv·2023-09-06·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-raspi, linux-raspi-5.4 vulnerabilities
linux-raspi, linux-raspi-5.4 vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system cr
OSV
linux-intel-iotg-5.15, linux-raspi vulnerabilities
osv·2023-09-06·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-intel-iotg-5.15, linux-raspi vulnerabilities
linux-intel-iotg-5.15, linux-raspi vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute ar
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
osv·2023-09-06·CVSS 5.5
CVE-2023-20593 [MEDIUM] linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Zheng Zhang discovered that the device-mapper implementation in the Linux
kernel did not properly handle locking during table_clear() operations. A
local attacker could use this to cause a denial of service (kernel
deadlock). (CVE-2023-2269)
It was discovered that a use-after-free vulnerability existed in the HFS+
file system implementation in the Linux kernel. A local attacker could
possibly use this to cause a denial of service (system crash).
(CVE-2023-2985)
OSV
linux-gkeop vulnerabilities
osv·2023-08-31·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-gkeop vulnerabilities
linux-gkeop vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly
OSV
linux-gkeop-5.15, linux-intel-iotg vulnerabilities
osv·2023-08-31·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-gkeop-5.15, linux-intel-iotg vulnerabilities
linux-gkeop-5.15, linux-intel-iotg vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute ar
OSV
linux-azure vulnerabilities
osv·2023-08-31·CVSS 5.5
CVE-2020-36691 [MEDIUM] linux-azure vulnerabilities
linux-azure vulnerabilities
It was discovered that the netlink implementation in the Linux kernel did
not properly validate policies when parsing attributes in some situations.
An attacker could use this to cause a denial of service (infinite
recursion). (CVE-2020-36691)
Billy Jheng Bing Jhong discovered that the CIFS network file system
implementation in the Linux kernel did not properly validate arguments to
ioctl() in some situations. A local attacker could possibly use this to
cause a denial of service (system crash). (CVE-2022-0168)
It was discovered that the ext4 file system implementation in the Linux
kernel contained a use-after-free vulnerability. An attacker could use this
to construct a malicious ext4 file system image that, when mounted, could
cause a denial of service (syst
OSV
linux-gcp-5.15 vulnerabilities
osv·2023-08-31·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-gcp-5.15 vulnerabilities
linux-gcp-5.15 vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2
OSV
linux-azure, linux-azure-5.15, linux-azure-fde vulnerabilities
osv·2023-08-31·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-azure, linux-azure-5.15, linux-azure-fde vulnerabilities
linux-azure, linux-azure-5.15, linux-azure-fde vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
William Zhao discovered that the Traffic Control (TC) subsystem in the
Linux kernel did not properly handle network packet retransmission in
certain situations. A local attacker could use this to cause a denial of
service (kernel deadlock). (CVE-2022-4269)
It was discovered that the NTFS file system implementation in the Linux
kernel did not properly check buffer indexes in certain situations, leading
to an out-of-bounds read vulnerability. A local attacker could possibly use
th
OSV
linux-gcp-5.4, linux-oracle-5.4 vulnerabilities
osv·2023-08-31·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-gcp-5.4, linux-oracle-5.4 vulnerabilities
linux-gcp-5.4, linux-oracle-5.4 vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system
OSV
linux-oem-6.1 vulnerabilities
osv·2023-08-29·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux-oem-6.1 vulnerabilities
linux-oem-6.1 vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Kevin Rich discovered that the netfilter subsystem in the Linux kernel did
not properly handle table rules flush in certain circumstances. A local
attacker could possibly use this to cause a denial of service (system
crash) or execute arbitrary code. (CVE-2023-3777)
Kevin Rich discovered that th
OSV
linux, linux-aws, linux-aws-6.2, linux-azure, linux-hwe-6.2, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-raspi vulnerabilities
osv·2023-08-29·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux, linux-aws, linux-aws-6.2, linux-azure, linux-hwe-6.2, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-raspi vulnerabilities
linux, linux-aws, linux-aws-6.2, linux-azure, linux-hwe-6.2, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-6.2, linux-raspi vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, lead
OSV
linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15 vu
osv·2023-08-29·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15 vu
linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15 vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle lockin
OSV
linux, linux-aws, linux-aws-5.4, linux-gcp, linux-hwe-5.4, linux-kvm, linux-oracle, linux-xilinx-zynqmp vulnerabilities
osv·2023-08-29·CVSS 6.5
CVE-2022-40982 [MEDIUM] linux, linux-aws, linux-aws-5.4, linux-gcp, linux-hwe-5.4, linux-kvm, linux-oracle, linux-xilinx-zynqmp vulnerabilities
linux, linux-aws, linux-aws-5.4, linux-gcp, linux-hwe-5.4, linux-kvm, linux-oracle, linux-xilinx-zynqmp vulnerabilities
Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local
attacker could use this to expose sensitive information. (CVE-2023-20593)
It was discovered that the universal 32bit network packet classifier
implementation in the Linux kernel did not properly perform reference
counting in some situations, leading to a use-after-free vulnerabili
OSV
CVE-2023-20593: An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information
osv·2023-07-24·CVSS 5.5
CVE-2023-20593 [MEDIUM] CVE-2023-20593: An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
No detection rules found.
No public exploits indexed.
Wiz
Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know | Wiz Blog
blogs_wiz·2023-07-26·CVSS 5.5
CVE-2023-20593 [MEDIUM] Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know | Wiz Blog
Researchers discovered a use-after-free flaw in AMD Zen 2 processors, which could allow a malicious actor to steal sensitive data, such as passwords and encryption keys. While many cloud environments have workloads running on affected CPUs, we estimate Zenbleed is not likely to be impactful in cloud environments.
We will update this blogpost as more information is published.
# What is CVE-2023-20593?
CVE-2023-20593 is a security vulnerability caused by improper handling of the `vzeroupper` instruction during speculative execution, which is a common performance-enhancing technique used in all modern processors. Unlike many other hardware vulnerabilities that rely on side-channels (ex. Rowhammer, Meltdown, and Spectre), this attack works reliably and with immediate results with few prereq
Wiz
Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know | Wiz Blog
blogs_wiz·2023-07-26·CVSS 5.5
CVE-2023-20593 [MEDIUM] Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know | Wiz Blog
Researchers discovered a use-after-free flaw in AMD Zen 2 processors, which could allow a malicious actor to steal sensitive data, such as passwords and encryption keys. While many cloud environments have workloads running on affected CPUs, we estimate Zenbleed is not likely to be impactful in cloud environments.
We will update this blogpost as more information is published.
## What is CVE-2023-20593?
vzeroupper
The researcher employed fuzzing and performance counters to identify specific hardware events. He validated his findings using the "Oracle Serialization" approach. By using the "Oracle Serialization" technique, the researcher compared the execution of a randomly generated program with its serialized oracle. This comparison revealed inconsistencies, ultimately leading to the dis
Bugzilla
CVE-2023-20593 hw: amd: Cross-Process Information Leak
bugzilla·2023-06-27·CVSS 5.5
CVE-2023-20593 [MEDIUM] CVE-2023-20593 hw: amd: Cross-Process Information Leak
CVE-2023-20593 hw: amd: Cross-Process Information Leak
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
Under specific microarchitectural circumstances, a register in “Zen 2” CPUs may not be written to 0 correctly. This may cause data from another process and/or thread to be stored in the YMM register, which may allow an attacker to potentially access sensitive information.
Refer:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7008.html
Discussion:
Affected Products:
“Zen 2” Architecture-based Client and Server platforms
Desktop
AMD RyzenTM 3000 Series Processors
AMD RyzenTM PRO 3000 Series Processors
AMD RyzenTM ThreadripperTM 3000 Series Processors
AMD RyzenTM 4000 Serie
http://seclists.org/fulldisclosure/2023/Jul/43http://www.openwall.com/lists/oss-security/2023/07/24/3http://www.openwall.com/lists/oss-security/2023/07/25/1http://www.openwall.com/lists/oss-security/2023/07/25/12http://www.openwall.com/lists/oss-security/2023/07/25/13http://www.openwall.com/lists/oss-security/2023/07/25/14http://www.openwall.com/lists/oss-security/2023/07/25/15http://www.openwall.com/lists/oss-security/2023/07/25/16http://www.openwall.com/lists/oss-security/2023/07/25/17http://www.openwall.com/lists/oss-security/2023/07/25/5http://www.openwall.com/lists/oss-security/2023/07/25/6http://www.openwall.com/lists/oss-security/2023/07/26/1http://www.openwall.com/lists/oss-security/2023/07/31/2http://www.openwall.com/lists/oss-security/2023/08/08/6http://www.openwall.com/lists/oss-security/2023/08/08/7http://www.openwall.com/lists/oss-security/2023/08/08/8http://www.openwall.com/lists/oss-security/2023/08/16/4http://www.openwall.com/lists/oss-security/2023/08/16/5http://www.openwall.com/lists/oss-security/2023/09/22/11http://www.openwall.com/lists/oss-security/2023/09/22/9http://www.openwall.com/lists/oss-security/2023/09/25/4http://www.openwall.com/lists/oss-security/2023/09/25/7http://xenbits.xen.org/xsa/advisory-433.htmlhttps://cmpxchg8b.com/zenbleed.htmlhttps://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2023/07/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/CP6WQO3CDPLE5O635N7TAL5KCZ6HZ4FE/https://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/https://lists.fedoraproject.org/archives/list/[email protected]/message/SD2G74BXS2SWOE3FIQJ6X76S3A7PDGML/https://security.netapp.com/advisory/ntap-20240531-0004/https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7008https://www.debian.org/security/2023/dsa-5459https://www.debian.org/security/2023/dsa-5461https://www.debian.org/security/2023/dsa-5462http://seclists.org/fulldisclosure/2023/Jul/43http://www.openwall.com/lists/oss-security/2023/07/24/3http://www.openwall.com/lists/oss-security/2023/07/25/1http://www.openwall.com/lists/oss-security/2023/07/25/12http://www.openwall.com/lists/oss-security/2023/07/25/13http://www.openwall.com/lists/oss-security/2023/07/25/14http://www.openwall.com/lists/oss-security/2023/07/25/15http://www.openwall.com/lists/oss-security/2023/07/25/16http://www.openwall.com/lists/oss-security/2023/07/25/17http://www.openwall.com/lists/oss-security/2023/07/25/5http://www.openwall.com/lists/oss-security/2023/07/25/6http://www.openwall.com/lists/oss-security/2023/07/26/1http://www.openwall.com/lists/oss-security/2023/07/31/2http://www.openwall.com/lists/oss-security/2023/08/08/6http://www.openwall.com/lists/oss-security/2023/08/08/7http://www.openwall.com/lists/oss-security/2023/08/08/8http://www.openwall.com/lists/oss-security/2023/08/16/4http://www.openwall.com/lists/oss-security/2023/08/16/5http://www.openwall.com/lists/oss-security/2023/09/22/11http://www.openwall.com/lists/oss-security/2023/09/22/9http://www.openwall.com/lists/oss-security/2023/09/25/4http://www.openwall.com/lists/oss-security/2023/09/25/7http://xenbits.xen.org/xsa/advisory-433.htmlhttps://cmpxchg8b.com/zenbleed.htmlhttps://lists.debian.org/debian-lts-announce/2023/07/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2023/07/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/CP6WQO3CDPLE5O635N7TAL5KCZ6HZ4FE/https://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO3KCKGRR/https://lists.fedoraproject.org/archives/list/[email protected]/message/SD2G74BXS2SWOE3FIQJ6X76S3A7PDGML/https://security.netapp.com/advisory/ntap-20240531-0004/https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7008https://www.debian.org/security/2023/dsa-5459https://www.debian.org/security/2023/dsa-5461https://www.debian.org/security/2023/dsa-5462
2023-07-24
Published