CVE-2023-20592: Medium severity amd epyc server firmware vulnerability
AMD Processors could provide weaker than expected security, caused by improper or unexpected behavior of the INVD instruction. A remote authenticated attacker could exploit this vulnerability to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
Other sources
Improper or unexpected behavior of the INVD in some of AMD CPU's may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU, potentially leading to a loss of guest virtual machine (VM) memory integrity.
Reference: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3005.html
— Red Hat
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20592?
CVE-2023-20592 is classified as a medium severity vulnerability affecting certain AMD processors.
How do I fix CVE-2023-20592?
To mitigate CVE-2023-20592, users should apply the firmware updates provided by AMD as detailed in the security bulletin.
What types of AMD processors are affected by CVE-2023-20592?
CVE-2023-20592 affects specific models in the AMD Epyc family of processors.
Can CVE-2023-20592 be exploited remotely?
Yes, CVE-2023-20592 can be exploited by a remote authenticated attacker under certain conditions.
What impact does CVE-2023-20592 have on virtual machines?
CVE-2023-20592 could potentially lead to a loss of data integrity in guest virtual machines by affecting cache line write-back behavior.