Уязвимость CVE-2023-20588: Информация

Описание

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

Важность: MEDIUM (5,5) Вектор: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Опубликовано: 8 августа 2023 г.
Изменено: 10 июня 2024 г.
Идентификатор типа ошибки: CWE-369

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7007
  • Vendor Advisory
https://www.debian.org/security/2023/dsa-5480
  • Third Party Advisory
https://www.debian.org/security/2023/dsa-5492
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/3
  • Mailing List
  • Third Party Advisory
http://xenbits.xen.org/xsa/advisory-439.html
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/4
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/8
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/5
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/7
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/8
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/9
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/27/1
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/5
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJTUVYZMP6BNF342DS3W7XGOGXC6JPN5/
  • Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGZCACEHT6ZZZGG36QQMGROBM4FLWYJX/
  • Mailing List
http://www.openwall.com/lists/oss-security/2023/10/03/9
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/12
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/15
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/14
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/13
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/16
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/1
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/2
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/3
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/4
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIOYP4ZOBML4RCUM3MHRFZUQL445MZM3/
  • Mailing List
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
  • Mailing List
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20240531-0005/
      1. Конфигурация 1

        cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

        cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

        cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

        Конфигурация 2

        cpe:2.3:o:amd:epyc_7351p_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7351p:-:*:*:*:*:*:*:*

        Конфигурация 3

        cpe:2.3:o:amd:epyc_7401p_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7401p:-:*:*:*:*:*:*:*

        Конфигурация 4

        cpe:2.3:o:amd:epyc_7551p_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7551p:-:*:*:*:*:*:*:*

        Конфигурация 5

        cpe:2.3:o:amd:epyc_7251_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7251:-:*:*:*:*:*:*:*

        Конфигурация 6

        cpe:2.3:o:amd:epyc_7261_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7261:-:*:*:*:*:*:*:*

        Конфигурация 7

        cpe:2.3:o:amd:epyc_7281_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7281:-:*:*:*:*:*:*:*

        Конфигурация 8

        cpe:2.3:o:amd:epyc_7301_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7301:-:*:*:*:*:*:*:*

        Конфигурация 9

        cpe:2.3:o:amd:epyc_7351_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7351:-:*:*:*:*:*:*:*

        Конфигурация 10

        cpe:2.3:o:amd:epyc_7371_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7371:-:*:*:*:*:*:*:*

        Конфигурация 11

        cpe:2.3:o:amd:epyc_7401_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7401:-:*:*:*:*:*:*:*

        Конфигурация 12

        cpe:2.3:o:amd:epyc_7451_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7451:-:*:*:*:*:*:*:*

        Конфигурация 13

        cpe:2.3:o:amd:epyc_7501_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7501:-:*:*:*:*:*:*:*

        Конфигурация 14

        cpe:2.3:o:amd:epyc_7551_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7551:-:*:*:*:*:*:*:*

        Конфигурация 15

        cpe:2.3:o:amd:epyc_7571_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7571:-:*:*:*:*:*:*:*

        Конфигурация 16

        cpe:2.3:o:amd:epyc_7601_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:epyc_7601:-:*:*:*:*:*:*:*

        Конфигурация 17

        cpe:2.3:o:amd:ryzen_5_pro_3400g_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_5_pro_3400g:-:*:*:*:*:*:*:*

        Конфигурация 18

        cpe:2.3:o:amd:ryzen_5_3400g_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_5_3400g:-:*:*:*:*:*:*:*

        Конфигурация 19

        cpe:2.3:o:amd:ryzen_5_pro_3400ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_5_pro_3400ge:-:*:*:*:*:*:*:*

        Конфигурация 20

        cpe:2.3:o:amd:ryzen_5_pro_3350g_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_5_pro_3350g:-:*:*:*:*:*:*:*

        Конфигурация 21

        cpe:2.3:o:amd:ryzen_5_pro_3350ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_5_pro_3350ge:-:*:*:*:*:*:*:*

        Конфигурация 22

        cpe:2.3:o:amd:ryzen_3_pro_3200g_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_3_pro_3200g:-:*:*:*:*:*:*:*

        Конфигурация 23

        cpe:2.3:o:amd:ryzen_3_3200g_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_3_3200g:-:*:*:*:*:*:*:*

        Конфигурация 24

        cpe:2.3:o:amd:ryzen_3_3200ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_3_3200ge:-:*:*:*:*:*:*:*

        Конфигурация 25

        cpe:2.3:o:amd:ryzen_3_pro_3200ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:ryzen_3_pro_3200ge:-:*:*:*:*:*:*:*

        Конфигурация 26

        cpe:2.3:o:amd:athlon_pro_300ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:athlon_pro_300ge:-:*:*:*:*:*:*:*

        Конфигурация 27

        cpe:2.3:o:amd:athlon_gold_3150ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:athlon_gold_3150ge:-:*:*:*:*:*:*:*

        Конфигурация 28

        cpe:2.3:o:amd:athlon_gold_pro_3150ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:athlon_gold_pro_3150ge:-:*:*:*:*:*:*:*

        Конфигурация 29

        cpe:2.3:o:amd:athlon_gold_3150g_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:athlon_gold_3150g:-:*:*:*:*:*:*:*

        Конфигурация 30

        cpe:2.3:o:amd:athlon_gold_pro_3150g_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:athlon_gold_pro_3150g:-:*:*:*:*:*:*:*

        Конфигурация 31

        cpe:2.3:o:amd:athlon_silver_3050ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:athlon_silver_3050ge:-:*:*:*:*:*:*:*

        Конфигурация 32

        cpe:2.3:o:amd:athlon_silver_pro_3125ge_firmware:-:*:*:*:*:*:*:*

        Running on/with:
        cpe:2.3:h:amd:athlon_silver_pro_3125ge:-:*:*:*:*:*:*:*

        Конфигурация 33

        cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:*

        Конфигурация 34

        cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

        cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

        cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

        Конфигурация 35

        cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

        cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*

        cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*

        cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

        cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
        End excliding
        10.0.17763.5206

        cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
        End excliding
        10.0.22000.2652

        cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
        End excliding
        10.0.22621.2861

        cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*
        End excliding
        10.0.19045.3803

        cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
        End excliding
        10.0.22631.2861

        cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*
        End excliding
        10.0.10240.20345

        cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
        End excliding
        10.0.14393.6529

        cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
        End excliding
        10.0.25398.584

        cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
        End excliding
        10.0.17763.5206

        cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
        End excliding
        10.0.14393.6529

        cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
        End excliding
        10.0.19044.3803