PT-2024-12275 · Amd+4 · Sev Firmware+4

Tom Dohrmann

·

Published

2023-12-19

·

Updated

2025-10-01

·

CVE-2023-31346

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SEV Firmware (affected versions not specified)
Description The issue is related to the failure to initialize memory in SEV Firmware, which may allow a privileged attacker to access stale data from other guests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

ALSA-2024:4262
ALSA-2024:4774
CESA-2024_4262
CVE-2023-31346
INFSA-2024_4262
INFSA-2024_4774
RHSA-2024:4262
RHSA-2024:4409
RHSA-2024:4733
RHSA-2024:4741
RHSA-2024:4774
RHSA-2024:5640
RHSA-2024:5883
RHSA-2024_4262
RHSA-2024_4774

Affected Products

Almalinux
Centos
Red Hat
Rocky Linux
Sev Firmware