CVE-2023-31347
published 2024-02-13CVE-2023-31347: Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
EPSS
0.46%
37.0th percentile
Due to a code bug in
Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a
guest to observe an incorrect TSC when Secure TSC is enabled potentially
resulting in a loss of guest integrity.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | 4th_gen_amd_epyc_processors | — | — |
| amd | epyc_7203_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7203p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_72f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7303_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7303p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7313p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7343_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7373x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_73f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7413_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7443p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7453_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7473x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_74f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7513_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7543p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7573x_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_75f3_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7643_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
| amd | epyc_7643p_firmware | < milanpi_1.0.0.c | milanpi_1.0.0.c |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
osv4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Insufficient check may lead to an incorrect TSC
vendor_redhat·2023-12-19·CVSS 4.9
CVE-2023-31347 [MEDIUM] CWE-168 kernel: Insufficient check may lead to an incorrect TSC
kernel: Insufficient check may lead to an incorrect TSC
Due to a code bug in
Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a
guest to observe an incorrect TSC when Secure TSC is enabled potentially
resulting in a loss of guest integrity.
A flaw was found in some AMD Hardware due to a code bug in the Secure_TSC, SEV firmware. This flaw allows an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled, potentially resulting in a loss of guest integrity.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (R
GHSA
GHSA-ggv6-7vfj-r2fw: Due to a code bug in
Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a
guest to observe an incorrect TSC when Secure TSC
ghsa_unreviewed·2024-02-13
CVE-2023-31347 [MEDIUM] CWE-682 GHSA-ggv6-7vfj-r2fw: Due to a code bug in
Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a
guest to observe an incorrect TSC when Secure TSC
Due to a code bug in
Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a
guest to observe an incorrect TSC when Secure TSC is enabled potentially
resulting in a loss of guest integrity.
OSV
CVE-2023-31347: Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC
osv·2024-02-13·CVSS 4.9
CVE-2023-31347 [MEDIUM] CVE-2023-31347: Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
No detection rules found.
No public exploits indexed.
2024-02-13
Published