USN-8887-2: Linux kernel (AWS) vulnerabilities
Ubuntu's USN-8887-2 patches AWS Linux kernels, including AMD SEV-SNP issue CVE-2023-20585 exploitable by a hypervisor attacker.
Ubuntu issued USN-8887-2 for Linux kernel packages used on Amazon Web Services. It addresses CVE-2023-20585, where some AMD processors did not properly perform Reverse Map Table checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. The update also fixes other kernel issues in architectures including ARM, MIPS, OpenRISC, PowerPC and RISC-V, plus NVDIMM drivers and the Handshake API, with no exploitation reported.
- USN-8887-2 covers Ubuntu Linux kernel packages for AWS.
- CVE-2023-20585 is an AMD RMP-check flaw affecting SEV-SNP memory integrity.
- Exploitation requires a local attacker who already has hypervisor access.
- Broader architecture and driver fixes are included; no in-the-wild use is stated.
Vulnerabilities mentionedAll →
- CVE-2023-205855.6<1%Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20585 | Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds… Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity. NVD description · AI analysis pending |
It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly use this to trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. (CVE-2023-20585) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - NVDIMM (Non-Volatile Memory Device) drivers; - Handshake API; - ARM32 architecture; - MIPS architecture; - OpenRISC architecture; - PowerPC architecture; - RISC-V…
This source does not provide full text. Read it at ubuntu.com.