CVE-2023-20584
MEDIUMDescription
IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.
Is your site exposed to CVE-2023-20584?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| amd | epyc_8024pn_firmware |
| amd | epyc_8024pn |
| amd | epyc_8024p_firmware |
| amd | epyc_8024p |
| amd | epyc_8124pn_firmware |
| amd | epyc_8124pn |
| amd | epyc_8124p_firmware |
| amd | epyc_8124p |
| amd | epyc_8224pn_firmware |
| amd | epyc_8224pn |
| amd | epyc_8224p_firmware |
| amd | epyc_8224p |
| amd | epyc_8324pn_firmware |
| amd | epyc_8324pn |
| amd | epyc_8324p_firmware |
| amd | epyc_8324p |
| amd | epyc_8434pn_firmware |
| amd | epyc_8434pn |
| amd | epyc_8434p_firmware |
| amd | epyc_8434p |
| amd | epyc_8534pn_firmware |
| amd | epyc_8534pn |
| amd | epyc_8534p_firmware |
| amd | epyc_8534p |
| amd | epyc_9734_firmware |
| amd | epyc_9734 |
| amd | epyc_9754s_firmware |
| amd | epyc_9754s |
| amd | epyc_9754_firmware |
| amd | epyc_9754 |
| amd | epyc_9184x_firmware |
| amd | epyc_9184x |
| amd | epyc_9384x_firmware |
| amd | epyc_9384x |
| amd | epyc_9684x_firmware |
| amd | epyc_9684x |
| amd | epyc_9124_firmware |
| amd | epyc_9124 |
| amd | epyc_9174f_firmware |
| amd | epyc_9174f |
| amd | epyc_9224_firmware |
| amd | epyc_9224 |
| amd | epyc_9254_firmware |
| amd | epyc_9254 |
| amd | epyc_9274f_firmware |
| amd | epyc_9274f |
| amd | epyc_9334_firmware |
| amd | epyc_9334 |
| amd | epyc_9354_firmware |
| amd | epyc_9354 |
| amd | epyc_9354p_firmware |
| amd | epyc_9354p |
| amd | epyc_9374f_firmware |
| amd | epyc_9374f |
| amd | epyc_9454_firmware |
| amd | epyc_9454 |
| amd | epyc_9454p_firmware |
| amd | epyc_9454p |
| amd | epyc_9474f_firmware |
| amd | epyc_9474f |
| amd | epyc_9534_firmware |
| amd | epyc_9534 |
| amd | epyc_9554_firmware |
| amd | epyc_9554 |
| amd | epyc_9554p_firmware |
| amd | epyc_9554p |
| amd | epyc_9634_firmware |
| amd | epyc_9634 |
| amd | epyc_9654_firmware |
| amd | epyc_9654 |
| amd | epyc_9654p_firmware |
| amd | epyc_9654p |
| amd | epyc_7203_firmware |
| amd | epyc_7203 |
| amd | epyc_7203p_firmware |
| amd | epyc_7203p |
| amd | epyc_72f3_firmware |
| amd | epyc_72f3 |
| amd | epyc_7303_firmware |
| amd | epyc_7303 |
| amd | epyc_7303p_firmware |
| amd | epyc_7303p |
| amd | epyc_7313_firmware |
| amd | epyc_7313 |
| amd | epyc_7313p_firmware |
| amd | epyc_7313p |
| amd | epyc_7343_firmware |
| amd | epyc_7343 |
| amd | epyc_73f3_firmware |
| amd | epyc_73f3 |
| amd | epyc_7373x_firmware |
| amd | epyc_7373x |
| amd | epyc_7413_firmware |
| amd | epyc_7413 |
| amd | epyc_7443_firmware |
| amd | epyc_7443 |
| amd | epyc_7443p_firmware |
| amd | epyc_7443p |
| amd | epyc_74f3_firmware |
| amd | epyc_74f3 |
| amd | epyc_7453_firmware |
| amd | epyc_7453 |
| amd | epyc_7473x_firmware |
| amd | epyc_7473x |
| amd | epyc_7513_firmware |
| amd | epyc_7513 |
| amd | epyc_7543_firmware |
| amd | epyc_7543 |
| amd | epyc_7543p_firmware |
| amd | epyc_7543p |
| amd | epyc_75f3_firmware |
| amd | epyc_75f3 |
| amd | epyc_7573x_firmware |
| amd | epyc_7573x |
| amd | epyc_7643_firmware |
| amd | epyc_7643 |
| amd | epyc_7773x_firmware |
| amd | epyc_7773x |
| amd | epyc_7643p_firmware |
| amd | epyc_7643p |
| amd | epyc_7663_firmware |
| amd | epyc_7663 |
| amd | epyc_7663p_firmware |
| amd | epyc_7663p |
| amd | epyc_7713_firmware |
| amd | epyc_7713 |
| amd | epyc_7713p_firmware |
| amd | epyc_7713p |
| amd | epyc_7763_firmware |
| amd | epyc_7763 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-20584? +
How severe is CVE-2023-20584? +
What products are affected by CVE-2023-20584? +
How do I check if I'm vulnerable to CVE-2023-20584? +
Related Vulnerabilities
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to …
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to …
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or …
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to …
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in …
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI …