Bug 2217863 (AMD-SN-3004, CVE-2023-20575) - CVE-2023-20575 hw: amd: SEV VM Power Side Channel Security Notice
Summary: CVE-2023-20575 hw: amd: SEV VM Power Side Channel Security Notice
Keywords:
Status: NEW
Alias: AMD-SN-3004, CVE-2023-20575
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2180682
TreeView+ depends on / blocked
 
Reported: 2023-06-27 10:07 UTC by Rohit Keshri
Modified: 2024-10-12 08:27 UTC (History)
43 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2023-06-27 10:07:38 UTC
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.

Refer:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3004.html

Comment 1 Rohit Keshri 2023-06-27 10:13:24 UTC
Affected Products:
 
*1st Gen AMD EPYCTM Processors
*2nd Gen AMD EPYCTM Processors
3rd Gen AMD EPYCTM Processors
4th Gen AMD EPYCTM Processors


Note You need to log in before you can comment on or make changes to this bug.