Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-31356

Published: October 3, 2024Last modified: June 6, 2025

Description

Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.

Severity score breakdown

ParameterValue
Base score4.4
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlinux-firmwareUnknown (20221109-r0)
Streamlinux-firmwareUnknown (20230625-r0)

References

ON THIS PAGE