CVE-2024-21978
published 2024-08-05CVE-2024-21978: Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data…
PriorityP336high7.9CVSS 3.1
AVLACLPRHUINSCCHIHAN
EPSS
0.49%
39.1th percentile
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 3rd_gen_amd_epyc_processors | >= various < MilanPI 1.0.0.D | MilanPI 1.0.0.D |
| amd | 4th_gen_amd_epyc_processors | >= various < GenoaPI 1.0.0.C | GenoaPI 1.0.0.C |
| amd | amd_epyc_embedded_7003 | >= various < EmbMilanPI-SP3 1.0.0.9 | EmbMilanPI-SP3 1.0.0.9 |
| amd | amd_epyc_embedded_9003 | >= various < EmbGenoaPI-SP5 1.0.0.7 | EmbGenoaPI-SP5 1.0.0.7 |
| amd | epyc_7203_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7203p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_72f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7303_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7303p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7313_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7313p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7343_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7373x_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_73f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7413_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7443_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7443p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7453_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7473x_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_74f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7513_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7543_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7543p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7573x_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_75f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
CVSS provenance
nvdv3.17.9HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rf8m-mggj-3g74: Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data
ghsa_unreviewed·2024-08-05
CVE-2024-21978 [MEDIUM] CWE-20 GHSA-rf8m-mggj-3g74: Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
Red Hat
linux-firmware: hw:amd: Improper input validation in SEV-SNP
vendor_redhat·2024-08-05·CVSS 6.0
CVE-2024-21978 [MEDIUM] CWE-20 linux-firmware: hw:amd: Improper input validation in SEV-SNP
linux-firmware: hw:amd: Improper input validation in SEV-SNP
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
A flaw was found in the AMD firmware. This vulnerability allows a malicious hypervisor to read or overwrite guest memory, potentially leading to data leakage or data corruption.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: linux-firmware (Red Hat Enterprise Linux 7) - Not affected
Package: linux-firmware (Red Hat Enterprise Linux 8) - Not affected
Package: li
No detection rules found.
No public exploits indexed.
2024-08-05
Published