PT-2024-11957 · Iommu+9 · Iommu+9

Published

2024-08-13

·

Updated

2025-08-13

·

CVE-2023-20584

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns the improper handling of certain special address ranges with invalid device table entries (DTEs) by the IOMMU. This may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults, potentially bypassing RMP checks in SEV-SNP and leading to a loss of guest integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

ALSA-2024:7481
ALSA-2024:7484
BDU:2025-03959
CESA-2024_7481
CVE-2023-20584
INFSA-2024_7481
INFSA-2024_7484
OESA-2024-2549
OESA-2024-2550
RHSA-2024:7418
RHSA-2024:7481
RHSA-2024:7483
RHSA-2024:7484
RHSA-2024_7481
RHSA-2024_7484
USN-7561-1

Affected Products

Almalinux
Astra Linux
Centos
Iommu
Linuxmint
Red Hat
Red Os
Rocky Linux
Sev-Snp
Ubuntu