PT-2023-8273 · Amd+1 · Amd Snp Guest Context Page Handler+1

CVE-2023-20519

·

Publicado

2023-11-14

·

Atualizado

2024-07-09

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AMD SNP Guest Context Page Handler (affected versions not specified)
Description A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent, resulting in a potential loss of guest integrity. The vulnerability is related to the use of memory after it has been freed, which could allow an attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00343
CVE-2023-20519
SUSE-SU-2023:4654-1
SUSE-SU-2023:4655-1
SUSE-SU-2023:4660-1
SUSE-SU-2023:4664-1
SUSE-SU-2023:4665-1
SUSE-SU-2024:2376-1

Produtos afetados

Amd Snp Guest Context Page Handler
Suse