Input validation error in 4th Gen AMD EPYC Processors and 3rd Gen AMD EPYC Processors - CVE-2023-20584

 

Input validation error in 4th Gen AMD EPYC Processors and 3rd Gen AMD EPYC Processors - CVE-2023-20584

Published: October 2, 2024


Vulnerability identifier: #VU97948
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20584
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of special address ranges with invalid device table entries (DTEs) in IOMMU. A local user can induce DTE faults to bypass RMP checks in SEV-SNP.


Affected software

4th Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
SimpliVity 325 Gen10 Plus
SimpliVity 325 Gen10
SimpliVity 325 Gen 11
HPE Gen11 BIOS
HPE ProLiant DL385 Gen11 Server
HPE ProLiant DL365 Gen11 Server
HPE ProLiant DL345 Gen11 Server
HPE ProLiant DL325 Gen11 Server
HPE Gen10 Plus BIOS
HPE ProLiant DL325 Gen10 Plus server
HPE ProLiant DL325 Gen10 Plus v2 server
HPE ProLiant DL345 Gen10 Plus server
HPE ProLiant DL365 Gen10 Plus server
HPE ProLiant DL385 Gen10 Plus server
HPE ProLiant DL385 Gen10 Plus v2 server
HPE Gen10 BIOS
HPE ProLiant DL325 Gen10 Server
HPE ProLiant DL385 Gen10 Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
amd64-microcode (Ubuntu package)
iwl5150-firmware
iwl5000-firmware
iwl6000-firmware
iwl3945-firmware
iwl2030-firmware
iwl2000-firmware
iwl135-firmware
iwl105-firmware
iwl6000g2a-firmware
iwl6000g2b-firmware
iwl7260-firmware
iwl3160-firmware
iwl100-firmware
iwl1000-firmware
iwl6050-firmware
iwl4965-firmware
linux-firmware (Red Hat package)
libertas-sd8686-firmware
libertas-sd8787-firmware
libertas-usb8388-firmware
libertas-usb8388-olpc-firmware
linux-firmware
linux-firmware-ti-connectivity
linux-firmware-netronome
linux-firmware-mrvl
linux-firmware-mediatek
linux-firmware-libertas
linux-firmware-iwlwifi
linux-firmware-cypress
linux-firmware-ath
Red Hat OpenShift Container Platform
OpenShift Virtualization
IBM Qradar SIEM
IBM QRadar Network Packet Capture
IBM Power Hardware Management Console (HMC)

How to mitigate CVE-2023-20584

Install updates from vendor's website.

4th Gen AMD EPYC Processors - update to GenoaPI 1.0.0.B
3rd Gen AMD EPYC Processors - update to MilanPI 1.0.0.C
SimpliVity 325 Gen10 Plus - update to SVTSPGen10-2024_0731
SimpliVity 325 Gen10 - update to SVTSPGen10-2024_0731
SimpliVity 325 Gen 11 - update to SVTSPGen11-2024_0731
HPE Gen11 BIOS - update to 1.58_01-04-2024
HPE ProLiant DL385 Gen11 Server - update to 1.58_01-04-2024
HPE ProLiant DL365 Gen11 Server - update to 1.58_01-04-2024
HPE ProLiant DL345 Gen11 Server - update to 1.58_01-04-2024
HPE ProLiant DL325 Gen11 Server - update to 1.58_01-04-2024
HPE Gen10 Plus BIOS - update to 2.84_08-17-2023
HPE ProLiant DL325 Gen10 Plus server - update to 2.84_08-17-2023
HPE ProLiant DL325 Gen10 Plus v2 server - update to 2.84_08-17-2023
HPE ProLiant DL345 Gen10 Plus server - update to 2.84_08-17-2023
HPE ProLiant DL365 Gen10 Plus server - update to 2.84_08-17-2023
HPE ProLiant DL385 Gen10 Plus server - update to 2.84_08-17-2023
HPE ProLiant DL385 Gen10 Plus v2 server - update to 2.84_08-17-2023
HPE Gen10 BIOS - update to 2.84_09-07-2023
HPE ProLiant DL325 Gen10 Server - update to 2.84_09-07-2023
HPE ProLiant DL385 Gen10 Server - update to 2.84_09-07-2023
amd64-microcode (Ubuntu package) - addressed in versions 3.20250311.1ubuntu0.24.04.1, 3.20250311.1ubuntu0.24.10.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.67, 4.13.52, 4.14.39, 4.15.36, 4.16.16, 4.17.1
OpenShift Virtualization - update to 4.13.11
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 11
iwl5150-firmware - update to 8.24.2.2-124
iwl5000-firmware - update to 8.83.5.1_1-124
iwl6000-firmware - update to 9.221.4.1-124
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
iwl3945-firmware - update to 15.32.2.9-124
iwl2030-firmware - update to 18.168.6.1-124
iwl2000-firmware - update to 18.168.6.1-124
iwl135-firmware - update to 18.168.6.1-124
iwl105-firmware - update to 18.168.6.1-124
iwl6000g2a-firmware - update to 18.168.6.1-124
iwl6000g2b-firmware - update to 18.168.6.1-124
iwl7260-firmware - update to 25.30.13.0-124
iwl3160-firmware - update to 25.30.13.0-124
iwl100-firmware - update to 39.31.5.1-124
iwl1000-firmware - update to 39.31.5.1-124
iwl6050-firmware - update to 41.28.5.1-124
iwl4965-firmware - update to 228.61.2.24-124
linux-firmware (Red Hat package) - addressed in versions 20240827-114.3.git3cff7109.el8_6, 20240827-124.git3cff7109.el8_10, 20240905-138.3.el9_2, 20240905-143.3.el9_4
libertas-sd8686-firmware - update to 20240827-124.git3cff7109
libertas-sd8787-firmware - update to 20240827-124.git3cff7109
libertas-usb8388-firmware - update to 20240827-124.git3cff7109
libertas-usb8388-olpc-firmware - update to 20240827-124.git3cff7109
linux-firmware - update to 20240827-124.git3cff7109
linux-firmware - update to 20241017-1
linux-firmware-ti-connectivity - update to 20241017-1
linux-firmware-netronome - update to 20241017-1
linux-firmware-mrvl - update to 20241017-1
linux-firmware-mediatek - update to 20241017-1
linux-firmware-libertas - update to 20241017-1
linux-firmware-iwlwifi - update to 20241017-1
linux-firmware-cypress - update to 20241017-1
linux-firmware-ath - update to 20241017-1

External References

Related Security Bulletins