Vulnerability CVE-2023-20588: Information

Description

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Published: Aug. 8, 2023
Modified: April 1, 2024
Error type identifier: CWE-369

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7007
  • Vendor Advisory
https://www.debian.org/security/2023/dsa-5480
  • Third Party Advisory
https://www.debian.org/security/2023/dsa-5492
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/3
  • Mailing List
  • Third Party Advisory
http://xenbits.xen.org/xsa/advisory-439.html
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/4
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/8
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/5
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/7
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/8
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/9
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/27/1
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/5
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJTUVYZMP6BNF342DS3W7XGOGXC6JPN5/
  • Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGZCACEHT6ZZZGG36QQMGROBM4FLWYJX/
  • Mailing List
http://www.openwall.com/lists/oss-security/2023/10/03/9
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/12
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/15
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/14
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/13
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/16
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/1
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/2
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/3
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/4
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIOYP4ZOBML4RCUM3MHRFZUQL445MZM3/
  • Mailing List
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
  • Mailing List
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:amd:epyc_7351p_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7351p:-:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:amd:epyc_7401p_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7401p:-:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:amd:epyc_7551p_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7551p:-:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:amd:epyc_7251_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7251:-:*:*:*:*:*:*:*

      Configuration 6

      cpe:2.3:o:amd:epyc_7261_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7261:-:*:*:*:*:*:*:*

      Configuration 7

      cpe:2.3:o:amd:epyc_7281_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7281:-:*:*:*:*:*:*:*

      Configuration 8

      cpe:2.3:o:amd:epyc_7301_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7301:-:*:*:*:*:*:*:*

      Configuration 9

      cpe:2.3:o:amd:epyc_7351_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7351:-:*:*:*:*:*:*:*

      Configuration 10

      cpe:2.3:o:amd:epyc_7371_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7371:-:*:*:*:*:*:*:*

      Configuration 11

      cpe:2.3:o:amd:epyc_7401_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7401:-:*:*:*:*:*:*:*

      Configuration 12

      cpe:2.3:o:amd:epyc_7451_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7451:-:*:*:*:*:*:*:*

      Configuration 13

      cpe:2.3:o:amd:epyc_7501_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7501:-:*:*:*:*:*:*:*

      Configuration 14

      cpe:2.3:o:amd:epyc_7551_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7551:-:*:*:*:*:*:*:*

      Configuration 15

      cpe:2.3:o:amd:epyc_7571_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7571:-:*:*:*:*:*:*:*

      Configuration 16

      cpe:2.3:o:amd:epyc_7601_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:epyc_7601:-:*:*:*:*:*:*:*

      Configuration 17

      cpe:2.3:o:amd:ryzen_5_pro_3400g_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_5_pro_3400g:-:*:*:*:*:*:*:*

      Configuration 18

      cpe:2.3:o:amd:ryzen_5_3400g_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_5_3400g:-:*:*:*:*:*:*:*

      Configuration 19

      cpe:2.3:o:amd:ryzen_5_pro_3400ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_5_pro_3400ge:-:*:*:*:*:*:*:*

      Configuration 20

      cpe:2.3:o:amd:ryzen_5_pro_3350g_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_5_pro_3350g:-:*:*:*:*:*:*:*

      Configuration 21

      cpe:2.3:o:amd:ryzen_5_pro_3350ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_5_pro_3350ge:-:*:*:*:*:*:*:*

      Configuration 22

      cpe:2.3:o:amd:ryzen_3_pro_3200g_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_3_pro_3200g:-:*:*:*:*:*:*:*

      Configuration 23

      cpe:2.3:o:amd:ryzen_3_3200g_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_3_3200g:-:*:*:*:*:*:*:*

      Configuration 24

      cpe:2.3:o:amd:ryzen_3_3200ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_3_3200ge:-:*:*:*:*:*:*:*

      Configuration 25

      cpe:2.3:o:amd:ryzen_3_pro_3200ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:ryzen_3_pro_3200ge:-:*:*:*:*:*:*:*

      Configuration 26

      cpe:2.3:o:amd:athlon_pro_300ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:athlon_pro_300ge:-:*:*:*:*:*:*:*

      Configuration 27

      cpe:2.3:o:amd:athlon_gold_3150ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:athlon_gold_3150ge:-:*:*:*:*:*:*:*

      Configuration 28

      cpe:2.3:o:amd:athlon_gold_pro_3150ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:athlon_gold_pro_3150ge:-:*:*:*:*:*:*:*

      Configuration 29

      cpe:2.3:o:amd:athlon_gold_3150g_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:athlon_gold_3150g:-:*:*:*:*:*:*:*

      Configuration 30

      cpe:2.3:o:amd:athlon_gold_pro_3150g_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:athlon_gold_pro_3150g:-:*:*:*:*:*:*:*

      Configuration 31

      cpe:2.3:o:amd:athlon_silver_3050ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:athlon_silver_3050ge:-:*:*:*:*:*:*:*

      Configuration 32

      cpe:2.3:o:amd:athlon_silver_pro_3125ge_firmware:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:amd:athlon_silver_pro_3125ge:-:*:*:*:*:*:*:*

      Configuration 33

      cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:*

      Configuration 34

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

      Configuration 35

      cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

      cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

      cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
      End excliding
      10.0.17763.5206

      cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
      End excliding
      10.0.22000.2652

      cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
      End excliding
      10.0.22621.2861

      cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*
      End excliding
      10.0.19045.3803

      cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
      End excliding
      10.0.22631.2861

      cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*
      End excliding
      10.0.10240.20345

      cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
      End excliding
      10.0.14393.6529

      cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
      End excliding
      10.0.25398.584

      cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
      End excliding
      10.0.17763.5206

      cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
      End excliding
      10.0.14393.6529

      cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
      End excliding
      10.0.19044.3803