USN-8888-2: Linux kernel (Azure) vulnerabilities
Ubuntu patched Azure Linux kernels, including AMD SEV-SNP flaw CVE-2023-20585 that a local hypervisor attacker could abuse.
Ubuntu issued USN-8888-2 for Linux kernel packages on Microsoft Azure. The notice includes CVE-2023-20585, in which some AMD processors failed Reverse Map Table checks when the IOMMU accessed certain host buffers, potentially letting a local attacker with hypervisor access cause an out-of-bounds condition and compromise SEV-SNP guest memory integrity. It also corrects additional kernel flaws across ARM64, ARM32, MIPS, OpenRISC, PowerPC, RISC-V, NVDIMM drivers and the Handshake API. The text does not say the issues are being exploited.
- USN-8888-2 updates Ubuntu's Azure Linux kernel packages.
- CVE-2023-20585 involves missing AMD RMP checks during IOMMU access.
- A local attacker with hypervisor access could affect SEV-SNP guest memory.
- Additional kernel subsystem flaws are also patched; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2023-205855.6<1%Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20585 | Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds… Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity. NVD description · AI analysis pending |
It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly use this to trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. (CVE-2023-20585) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - NVDIMM (Non-Volatile Memory Device) drivers; - Handshake API; - ARM32 architecture; - MIPS architecture; - OpenRISC architecture; - PowerPC architecture; - RISC-V…
This source does not provide full text. Read it at ubuntu.com.