CVE-2023-20584

Published: October 3, 2024Last modified: June 6, 2025

Description

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.

Severity score breakdown

ParameterValue
Base score6
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlinux-firmwareUnknown (20221109-r0)
Streamlinux-firmwareUnknown (20230625-r0)

References

ON THIS PAGE