CVE-2024-21980
published 2024-08-05CVE-2024-21980: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in…
PriorityP338high7.9CVSS 3.1
AVLACLPRHUINSCCHIHAN
EPSS
0.45%
36.3th percentile
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 3rd_gen_amd_epyc_processors | >= various < MilanPI 1.0.0.D | MilanPI 1.0.0.D |
| amd | 4th_gen_amd_epyc_processors | >= various < GenoaPI 1.0.0.C | GenoaPI 1.0.0.C |
| amd | amd_epyc_embedded_7003 | >= various < EmbMilanPI-SP3 1.0.0.9 | EmbMilanPI-SP3 1.0.0.9 |
| amd | amd_epyc_embedded_9003 | >= various < EmbGenoaPI-SP5 1.0.0.7 | EmbGenoaPI-SP5 1.0.0.7 |
| amd | epyc_7203_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7203p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_72f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7303_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7303p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7313_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7313p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7343_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7373x_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_73f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7413_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7443_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7443p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7453_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7473x_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_74f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7513_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7543_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7543p_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_7573x_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
| amd | epyc_75f3_firmware | < milanpi_1.0.0.d | milanpi_1.0.0.d |
CVSS provenance
nvdv3.17.9HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9j5-9g8p-5h5q: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resu
ghsa_unreviewed·2024-08-05
CVE-2024-21980 [HIGH] CWE-119 GHSA-q9j5-9g8p-5h5q: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resu
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
Red Hat
kernel: hw:amd: Guest Memory Vulnerability in SNP
vendor_redhat·2024-08-05·CVSS 7.9
CVE-2024-21980 [HIGH] CWE-119 kernel: hw:amd: Guest Memory Vulnerability in SNP
kernel: hw:amd: Guest Memory Vulnerability in SNP
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
A flaw was found in SNP firmware. This vulnerability allows a malicious hypervisor to overwrite a guest's memory or UMC seed, resulting in loss of confidentiality and integrity via improper restriction of write operations.
Statement: Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third-party vendor and Red
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-05
Published