CVE-2023-31346: Medium severity AMD Epyc 7773x Firmware vulnerability
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
Other sources
Reserved fields in guest message responses may not be zero initialized. The size of(snpmsgcpuidrspt) bytes are zero initialized, but ReqHdr->msgsize is sent out for the request. If a guest sets ReqHdr->msgsize to a higher value than sizeof(snpmsgcpuidrspt), the firmware may leak stale memory from gpSevScratchBuf+(PAGESIZE4K3). The stale data leaked to software may contain guest private data or SEV firmware sensitive data.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31346?
CVE-2023-31346 is considered a high-severity vulnerability due to potential sensitive information exposure.
How do I fix CVE-2023-31346?
To mitigate CVE-2023-31346, update the affected AMD Epyc firmware to the latest version available that addresses the vulnerability.
Who is affected by CVE-2023-31346?
CVE-2023-31346 affects local authenticated users of certain AMD Epyc processors running vulnerable firmware versions.
What types of exploitation does CVE-2023-31346 allow?
CVE-2023-31346 allows an attacker to access stale data from other guests, potentially leading to information disclosure.
Which products are impacted by CVE-2023-31346?
Products impacted by CVE-2023-31346 include various AMD Epyc processor firmware versions, specifically below milanpi_1.0.0.c.