CVE-2023-20519

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
14/11/2023
Last modified:
21/11/2023

Description

A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest&amp;#39;s migration agent resulting in a potential loss of guest integrity.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amd:milanpi_firmware:*:*:*:*:*:*:*:* 1.0.0.a (excluding)
cpe:2.3:h:amd:milanpi:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:genoapi_firmware:*:*:*:*:*:*:*:* 1.0.0.3 (excluding)
cpe:2.3:h:amd:genoapi:-:*:*:*:*:*:*:*