CVE-2023-31356
published 2024-08-13CVE-2023-31356: Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data…
PriorityP418medium4.4CVSS 3.1
AVLACLPRHUINSUCNIHAN
EPSS
0.20%
9.9th percentile
Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt guest private memory, potentially
resulting in a loss of data integrity.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | amd64-microcode | < amd64-microcode 3.20240820.1~deb12u1 (bookworm) | amd64-microcode 3.20240820.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
osv6.0MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
AMD Microcode vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 5.3
CVE-2023-20584 [MEDIUM] AMD Microcode vulnerabilities
Title: AMD Microcode vulnerabilities
Summary: Several security issues were fixed in AMD Microcode.
It was discovered that AMD Microcode incorrectly handled memory addresses.
An attacker with local administrator privilege could possibly use this
issue to cause loss of integrity of a confidential guest running under AMD
SEV-SNP. (CVE-2023-20584, CVE-2023-31356)
Josh Eads, Kristoffer Janke, Eduardo Nava, Tavis Ormandy and Matteo Rizzo
discovered that AMD Microcode incorrectly verified signatures. An attacker
with local administrator privilege could possibly use this issue to cause
loss of confidentiality and integrity of a confidential guest running under
AMD SEV-SNP. (CVE-2024-56161)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary c
Red Hat
kernel: hw:amd: Incomplete system memory cleanup in SEV firmware corrupt guest private memory
vendor_redhat·2024-08-13·CVSS 4.4
CVE-2023-31356 [MEDIUM] kernel: hw:amd: Incomplete system memory cleanup in SEV firmware corrupt guest private memory
kernel: hw:amd: Incomplete system memory cleanup in SEV firmware corrupt guest private memory
Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt guest private memory, potentially
resulting in a loss of data integrity.
A flaw was found in hw in the SNP-SEV firmware. This flaw could allow a privileged attacker to corrupt a guest's private memory, potentially resulting in the loss of data integrity of the guest.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: linux-firmware (Red Hat Enterprise Linux 10) - Not affected
Package: linux-firmware
Debian
CVE-2023-31356: amd64-microcode - Incomplete system memory cleanup in SEV firmware could allow a privileged attack...
vendor_debian·2023·CVSS 4.4
CVE-2023-31356 [MEDIUM] CVE-2023-31356: amd64-microcode - Incomplete system memory cleanup in SEV firmware could allow a privileged attack...
Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.
Scope: local
bookworm: resolved (fixed in 3.20240820.1~deb12u1)
bullseye: resolved (fixed in 3.20240820.1~deb11u1)
forky: resolved (fixed in 3.20240820.1)
sid: resolved (fixed in 3.20240820.1)
trixie: resolved (fixed in 3.20240820.1)
OSV
amd64-microcode vulnerabilities
osv·2025-06-09·CVSS 6.0
CVE-2023-20584 [MEDIUM] amd64-microcode vulnerabilities
amd64-microcode vulnerabilities
It was discovered that AMD Microcode incorrectly handled memory addresses.
An attacker with local administrator privilege could possibly use this
issue to cause loss of integrity of a confidential guest running under AMD
SEV-SNP. (CVE-2023-20584, CVE-2023-31356)
Josh Eads, Kristoffer Janke, Eduardo Nava, Tavis Ormandy and Matteo Rizzo
discovered that AMD Microcode incorrectly verified signatures. An attacker
with local administrator privilege could possibly use this issue to cause
loss of confidentiality and integrity of a confidential guest running under
AMD SEV-SNP. (CVE-2024-56161)
GHSA
GHSA-3w7r-v4fr-r43w: Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt guest private memory, potentially
resulting in a loss of
ghsa_unreviewed·2024-08-13
CVE-2023-31356 [MEDIUM] CWE-459 GHSA-3w7r-v4fr-r43w: Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt guest private memory, potentially
resulting in a loss of
Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt guest private memory, potentially
resulting in a loss of data integrity.
OSV
CVE-2023-31356: Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of
osv·2024-08-13·CVSS 4.4
CVE-2023-31356 [MEDIUM] CVE-2023-31356: Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of
Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-13
Published