USN-8887-1: Linux kernel vulnerabilities
Ubuntu patched Linux kernel flaws, including an AMD SEV-SNP memory integrity issue tracked as CVE-2023-20585.
Ubuntu published USN-8887-1 for multiple Linux kernel vulnerabilities spanning ARM, MIPS, PowerPC, RISC-V, NVDIMM, and other subsystems. CVE-2023-20585 concerns AMD processors that fail Reverse Map Table checks when the IOMMU accesses certain host buffers; a local attacker with hypervisor access could trigger an out-of-bounds condition and compromise SEV-SNP guest memory integrity. The notice does not report active exploitation.
- USN-8887-1 fixes multiple Linux kernel flaws across several architectures and drivers.
- CVE-2023-20585: flawed AMD RMP checks can let a local hypervisor attacker affect SEV-SNP guest memory.
- No exploitation in the wild is reported.
Vulnerabilities mentionedAll →
- CVE-2023-205855.6<1%Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20585 | Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds… Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in a potential loss of confidential guest integrity. NVD description · AI analysis pending |
It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly use this to trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. (CVE-2023-20585) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - NVDIMM (Non-Volatile Memory Device) drivers; - Handshake API; - ARM32 architecture; - MIPS architecture; - OpenRISC architecture; - PowerPC architecture; - RISC-V…
This source does not provide full text. Read it at ubuntu.com.