PT-2023-3704 · Amd+10 · Amd Ryzen+11

Tavis Ormandy

·

Publicado

2023-07-24

·

Atualizado

2025-02-13

·

CVE-2023-20593

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AMD Zen 2 processors (affected versions not specified)
Description The issue in AMD Zen 2 processors, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. This is due to a use-after-free vulnerability, which can be exploited to track the contents of registers during the execution of other processes on the same CPU core. Researchers have found that 62% of AWS environments are potentially vulnerable to this issue, and it may affect various AMD Ryzen processors. The vulnerability can be used to steal confidential data, such as passwords and encryption keys.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. However, AMD has begun releasing microcode updates, and clients are recommended to apply AGESA firmware fixes. As a temporary workaround, consider disabling or restricting the use of vulnerable components until a patch is available. Additionally, users can apply kernel-side mitigations to protect themselves until AMD releases fixed microcode updates for all affected CPUs.

Exploit

Generation of Error Message Containing Sensitive Information

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:5068
ALSA-2023:5069
ALSA-2023:5091
ALSA-2023:5244
ALSA-2023:5245
ALT-PU-2023-4764
ALT-PU-2023-7439
BDU:2023-03992
CESA-2023_5244
CESA-2023_5245
CESA-2023_5255
CESA-2023_7513
CVE-2023-20593
DLA-3508-1
DLA-3511-1
DLA-3512-1
DSA-5459-1
DSA-5461-1
DSA-5462-1
MGASA-2023-0242
MGASA-2023-0243
MGASA-2023-0244
OPENSUSE-SU-2023_3171-1
OPENSUSE-SU-2023_3172-1
OPENSUSE-SU-2023_3180-1
OPENSUSE-SU-2023_3182-1
OPENSUSE-SU-2023_3302-1
OPENSUSE-SU-2023_3318-1
OPENSUSE-SU-2023_3391-1
OPENSUSE-SU-2023_3392-1
OPENSUSE-SU-2023_3395-1
OPENSUSE-SU-2023_3447-1
OPENSUSE-SU-2024:13080-1
OPENSUSE-SU-2024:13095-1
OPENSUSE-SU-2024:13105-1
OPENSUSE-SU-2024:13183-1
OPENSUSE-SU-2024:13704-1
OPENSUSE-SU-2025:14769-1
OPENSUSE-SU-2025:14770-1
OPENSUSE-SU-2025:14771-1
OPENSUSE-SU-2025:14772-1
OPENSUSE-SU-2025:14773-1
OPENSUSE-SU-2025:14774-1
OPENSUSE-SU-2025:14775-1
OPENSUSE-SU-2025:14776-1
OPENSUSE-SU-2025:14777-1
OPENSUSE-SU-2025:14778-1
OPENSUSE-SU-2025:14779-1
OPENSUSE-SU-2025:14780-1
OPENSUSE-SU-2025:14781-1
OPENSUSE-SU-2025:14782-1
OPENSUSE-SU-2025:14783-1
OPENSUSE-SU-2025:14784-1
OPENSUSE-SU-2025:14785-1
OPENSUSE-SU-2025:14786-1
OPENSUSE-SU-2025:14787-1
OPENSUSE-SU-2025:14788-1
OPENSUSE-SU-2025:14789-1
OPENSUSE-SU-2025:14790-1
OPENSUSE-SU-2025:14791-1
OPENSUSE-SU-2025:14792-1
OPENSUSE-SU-2025:14793-1
OPENSUSE-SU-2025:14794-1
OPENSUSE-SU-2025:14795-1
OPENSUSE-SU-2025:14796-1
OPENSUSE-SU-2025:14797-1
OPENSUSE-SU-2025:14798-1
OPENSUSE-SU-2025:14799-1
OPENSUSE-SU-2025:14800-1
OPENSUSE-SU-2025:14801-1
OPENSUSE-SU-2025:14804-1
RHSA-2023:4696
RHSA-2023:4699
RHSA-2023:4789
RHSA-2023:4819
RHSA-2023:4821
RHSA-2023:5068
RHSA-2023:5069
RHSA-2023:5091
RHSA-2023:5244
RHSA-2023:5245
RHSA-2023:5255
RHSA-2023:5419
RHSA-2023:5591
RHSA-2023:5607
RHSA-2023:7244
RHSA-2023:7382
RHSA-2023:7389
RHSA-2023:7401
RHSA-2023:7513
RHSA-2023:7551
RHSA-2023:7557
RHSA-2023:7665
RHSA-2023:7782
RHSA-2023_4819
RHSA-2023_4821
RHSA-2023_5068
RHSA-2023_5069
RHSA-2023_5091
RHSA-2023_5244
RHSA-2023_5245
RHSA-2023_5255
RHSA-2023_7513
RHSA-2024:0402
RHSA-2024:0403
RHSA-2024:0561
RLSA-2023:5091
RLSA-2023:5244
RXSA-2023:5244
SUSE-SU-2023:2986-1
SUSE-SU-2023:3001-1
SUSE-SU-2023:3006-1
SUSE-SU-2023:3019-1
SUSE-SU-2023:3020-1
SUSE-SU-2023:3022-1
SUSE-SU-2023:3171-1
SUSE-SU-2023:3172-1
SUSE-SU-2023:3180-1
SUSE-SU-2023:3182-1
SUSE-SU-2023:3206-1
SUSE-SU-2023:3302-1
SUSE-SU-2023:3309-1
SUSE-SU-2023:3318-1
SUSE-SU-2023:3324-1
SUSE-SU-2023:3333-1
SUSE-SU-2023:3349-1
SUSE-SU-2023:3390-1
SUSE-SU-2023:3391-1
SUSE-SU-2023:3392-1
SUSE-SU-2023:3395-1
SUSE-SU-2023:3421-1
SUSE-SU-2023:3446-1
SUSE-SU-2023:3447-1
SUSE-SU-2023:3494-1
SUSE-SU-2023:3495-1
SUSE-SU-2023:3496-1
SUSE-SU-2023:3894-1
SUSE-SU-2023:3895-1
SUSE-SU-2023:3902-1
SUSE-SU-2023:3903-1
SUSE-SU-2023_2986-1
SUSE-SU-2023_3001-1
SUSE-SU-2023_3006-1
SUSE-SU-2023_3019-1
SUSE-SU-2023_3020-1
SUSE-SU-2023_3022-1
SUSE-SU-2023_3171-1
SUSE-SU-2023_3172-1
SUSE-SU-2023_3180-1
SUSE-SU-2023_3182-1
SUSE-SU-2023_3206-1
SUSE-SU-2024:0884-1
SUSE-SU-2024:0885-1
SUSE-SU-2024_0884-1
SUSE-SU-2024_0885-1
USN-6244-1
USN-6315-1
USN-6316-1
USN-6317-1
USN-6318-1
USN-6321-1
USN-6324-1
USN-6325-1
USN-6328-1
USN-6329-1
USN-6330-1
USN-6331-1
USN-6332-1
USN-6342-1
USN-6342-2
USN-6346-1
USN-6348-1
USN-6357-1
USN-6385-1
USN-6397-1
USN-6532-1

Produtos afetados

Alt Linux
Amd Ryzen
Amd Zen 2
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu