PT-2019-6437 · Advanced Micro Devices Inc.+2 · Amd Platform Security Processor+3

Cfir Cohen

·

Published

2019-02-19

·

Updated

2025-02-13

·

CVE-2019-9836

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP) 0.17 build 11 and earlier
Description The issue is related to an insecure cryptographic implementation in AMD's Secure Encrypted Virtualization (SEV) technology, which can be exploited by a remote attacker to access confidential data. This vulnerability allows for the compromise of protected data by recovering platform Diffie-Hellman keys via an invalid curve attack. The SEV technology provides transparent memory encryption for virtual machines at the hardware level, ensuring that only the current guest system can access decrypted data, while other virtual machines and the hypervisor can only access encrypted data.
Recommendations For Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP) 0.17 build 11 and earlier, consider disabling the SEV feature until a patch or update is available to address the insecure cryptographic implementation. As a temporary workaround, restrict access to sensitive data and virtual machines to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07286
CVE-2019-9836
DLA-3511-1
DSA-5459-1
MGASA-2019-0207
OPENSUSE-SU-2019:1770-1
OPENSUSE-SU-2019_1770-1
OPENSUSE-SU-2024:10894-1
OPENSUSE-SU-2025:14769-1
OPENSUSE-SU-2025:14770-1
OPENSUSE-SU-2025:14771-1
OPENSUSE-SU-2025:14772-1
OPENSUSE-SU-2025:14773-1
OPENSUSE-SU-2025:14774-1
OPENSUSE-SU-2025:14775-1
OPENSUSE-SU-2025:14776-1
OPENSUSE-SU-2025:14777-1
OPENSUSE-SU-2025:14778-1
OPENSUSE-SU-2025:14779-1
OPENSUSE-SU-2025:14780-1
OPENSUSE-SU-2025:14781-1
OPENSUSE-SU-2025:14782-1
OPENSUSE-SU-2025:14783-1
OPENSUSE-SU-2025:14784-1
OPENSUSE-SU-2025:14785-1
OPENSUSE-SU-2025:14786-1
OPENSUSE-SU-2025:14787-1
OPENSUSE-SU-2025:14788-1
OPENSUSE-SU-2025:14789-1
OPENSUSE-SU-2025:14790-1
OPENSUSE-SU-2025:14791-1
OPENSUSE-SU-2025:14792-1
OPENSUSE-SU-2025:14793-1
OPENSUSE-SU-2025:14794-1
OPENSUSE-SU-2025:14795-1
OPENSUSE-SU-2025:14796-1
OPENSUSE-SU-2025:14797-1
OPENSUSE-SU-2025:14798-1
OPENSUSE-SU-2025:14799-1
OPENSUSE-SU-2025:14800-1
OPENSUSE-SU-2025:14801-1
OPENSUSE-SU-2025:14804-1
SUSE-SU-2019:1792-1
SUSE-SU-2019:1802-1
SUSE-SU-2019:1803-1
SUSE-SU-2019_1792-1
SUSE-SU-2019_1802-1
SUSE-SU-2019_1803-1

Affected Products

Astra Linux
Amd Platform Security Processor
Amd Secure Encrypted Virtualization
Suse