CVE-2023-31346
published 2024-02-13CVE-2023-31346: Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
PriorityP426medium6CVSS 3.1
AVLACLPRHUINSCCHINAN
EPSS
0.31%
22.9th percentile
Failure to initialize
memory in SEV Firmware may allow a privileged attacker to access stale data
from other guests.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | 4th_gen_amd_epyc_processors | — | — |
| amd | epyc_7203_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7203p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_72f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7303_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7303p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7343_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7373x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_73f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7413_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7453_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7473x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_74f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7513_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7573x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_75f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7643_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7643p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
osv6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rvmr-97cf-9f3m: Failure to initialize
memory in SEV Firmware may allow a privileged attacker to access stale data
from other guests
ghsa_unreviewed·2024-02-13
CVE-2023-31346 [MEDIUM] CWE-284 GHSA-rvmr-97cf-9f3m: Failure to initialize
memory in SEV Firmware may allow a privileged attacker to access stale data
from other guests
Failure to initialize
memory in SEV Firmware may allow a privileged attacker to access stale data
from other guests.
OSV
CVE-2023-31346: Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests
osv·2024-02-13·CVSS 6.0
CVE-2023-31346 [MEDIUM] CVE-2023-31346: Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
Red Hat
kernel: Reserved fields in guest message responses may not be zero initialized
vendor_redhat·2023-12-19·CVSS 6.0
CVE-2023-31346 [MEDIUM] CWE-200 kernel: Reserved fields in guest message responses may not be zero initialized
kernel: Reserved fields in guest message responses may not be zero initialized
Failure to initialize
memory in SEV Firmware may allow a privileged attacker to access stale data
from other guests.
A flaw was found in some AMD CPUs where the guest message responses have not been zero-initialized. This issue may allow a local attacker with the ability to run arbitrary code on a container or virtual machine to discover sensitive information contained in the host system's memory.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: linux-firmware (Red Hat Enterprise Linux 6) - Affected
Packag
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-13
Published