Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-20569

Published: August 8, 2023Last modified: September 5, 2023

Description

A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled?address, potentially leading to information disclosure.

Severity score breakdown

ParameterValue
Base score4.7
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Notes

From https://ubuntu.com/security/CVE-2023-20569 the upstream patches are: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=f2eb058afc57348cde66852272d6bf11da1eef8f https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=b250b32ab1d044953af2dc5e790819a7703b7ee6

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlinux-firmwareFixed (20221214-r5)
Streamlinux-firmwareFixed (20230919-r0)

References

ON THIS PAGE