SB2024072522 - Multiple vulnerabilities in SEV-SNP firmware on AMD processors
Published: July 25, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper Initialization (CVE-ID: CVE-2023-31346)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to improper initialization in SEV Firmware. A local user can run a specially crafted application to access stale data from other guests.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2023-31347)
The vulnerability allows a local user to modify data on other guests.
The vulnerability exists due to improper privilege management in Secure_TSC, SEV firmware. A local user can cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
Remediation
Install update from vendor's website.