CVE-2023-20592
Published: 14 November 2023
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
Notes
Author | Note |
---|---|
alexmurray | The microcode revisions listed in the AMD advisory AMD-SB-3005 were contained in the upstream commit b250b32ab1d044953af2dc5e790819a7703b7ee6 - this was already provided to the various Ubuntu releases in USN-6319-1 for CVE-2023-20569, as such they are not affected by this CVE. |
Priority
Status
Package | Release | Status |
---|---|---|
amd64-microcode Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(3.20191021.1+really3.20181128.1~ubuntu0.18.04.1+esm2)
|
focal |
Not vulnerable
(3.20191218.1ubuntu1.2)
|
|
jammy |
Not vulnerable
(3.20191218.1ubuntu2.2)
|
|
lunar |
Not vulnerable
(3.20220411.1ubuntu3.2)
|
|
mantic |
Not vulnerable
(3.20230808.1.1ubuntu1)
|
|
trusty |
Ignored
(no real-world users)
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(3.20191021.1+really3.20180524.1~ubuntu0.16.04.2+esm2)
|
|
Patches: upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=b250b32ab1d044953af2dc5e790819a7703b7ee6 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |