CVE-2023-20588
Vulnerability Summary
Timeline
Description
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 11.32%• Percentile: 96%
Techniques & Countermeasures
- CWE-369•Divide By Zero
The product divides a value by zero.
Affected Systems
- amd•athlon_gold_3150g_firmware
na
- amd•athlon_gold_3150ge_firmware
na
- amd•athlon_gold_pro_3150g_firmware
na
- amd•athlon_gold_pro_3150ge_firmware
na
- amd•athlon_pro_300ge_firmware
na
- amd•athlon_silver_3050ge_firmware
na
- amd•athlon_silver_pro_3125ge_firmware
na
- amd•athlon™ 3000 series processors with radeon™ graphics
various
- amd•athlon™ pro 3000 series processors with radeon™ vega graphics
Various
- amd•epyc_7251_firmware
na
- amd•epyc_7261_firmware
na
- amd•epyc_7281_firmware
na
- amd•epyc_7301_firmware
na
- amd•epyc_7351_firmware
na
- amd•epyc_7351p_firmware
na
- amd•epyc_7371_firmware
na
- amd•epyc_7401_firmware
na
- amd•epyc_7401p_firmware
na
- amd•epyc_7451_firmware
na
- amd•epyc_7501_firmware
na
- amd•epyc_7551_firmware
na
- amd•epyc_7551p_firmware
na
- amd•epyc_7571_firmware
na
- amd•epyc_7601_firmware
na
- amd•epyc™ 7001 processors
various
- amd•ryzen_3_3200g_firmware
na
- amd•ryzen_3_3200ge_firmware
na
- amd•ryzen_3_pro_3200g_firmware
na
- amd•ryzen_3_pro_3200ge_firmware
na
- amd•ryzen_5_3400g_firmware
na
- amd•ryzen_5_pro_3350g_firmware
na
- amd•ryzen_5_pro_3350ge_firmware
na
- amd•ryzen_5_pro_3400g_firmware
na
- amd•ryzen_5_pro_3400ge_firmware
na
- amd•ryzen™ 3000 series processors with radeon™ graphics
various
- amd•ryzen™ pro 3000 series processors with radeon™ vega graphics
various
- alpine•xen
< 4.15.5-r2 | < 4.16.5-r2 | < 4.16.5-r2 | < 4.17.2-r2 | < 4.17.2-r2 | < 4.17.2-r2 | < 4.17.2-r2 | < 4.17.2-r2 | < 4.17.2-r2 | < 4.17.2-r2
- debian•linux
< 5.10.197-1 | < 6.1.52-1 | < 6.4.13-1 | < 6.4.13-1
- debian•xen
all | < 4.17.2+76-ge1f9cb16e2-1~deb12u1 | < 4.17.2+55-g0b56bed864-1 | < 4.17.2+55-g0b56bed864-1
- ubuntu•linux
all | < 4.4.0-250.284 | < 4.15.0-221.232 | < 5.4.0-163.180 | < 5.15.0-84.93
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 4.4.0-1127.133 | < 4.4.0-1164.179 | < 4.15.0-1164.177 | < 5.4.0-1110.119 | < 5.15.0-1045.50
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1045.50~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1110.119~18.04.1
- ubuntu•linux-aws-5.8
all
Showing first 50 affected entries in server-rendered view.
References (46)
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7007
- https://www.debian.org/security/2023/dsa-5480
- https://www.debian.org/security/2023/dsa-5492
- http://www.openwall.com/lists/oss-security/2023/09/25/3
- http://www.openwall.com/lists/oss-security/2023/09/25/4
- http://xenbits.xen.org/xsa/advisory-439.html
- http://www.openwall.com/lists/oss-security/2023/09/25/5
- http://www.openwall.com/lists/oss-security/2023/09/25/8
- http://www.openwall.com/lists/oss-security/2023/09/25/7
- http://www.openwall.com/lists/oss-security/2023/09/26/5
- http://www.openwall.com/lists/oss-security/2023/09/26/8
- http://www.openwall.com/lists/oss-security/2023/09/26/9
- http://www.openwall.com/lists/oss-security/2023/09/27/1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJTUVYZMP6BNF342DS3W7XGOGXC6JPN5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGZCACEHT6ZZZGG36QQMGROBM4FLWYJX/
- http://www.openwall.com/lists/oss-security/2023/10/03/14
- http://www.openwall.com/lists/oss-security/2023/10/03/9
- http://www.openwall.com/lists/oss-security/2023/10/03/15
- http://www.openwall.com/lists/oss-security/2023/10/03/12
- http://www.openwall.com/lists/oss-security/2023/10/03/13
- http://www.openwall.com/lists/oss-security/2023/10/03/16
- http://www.openwall.com/lists/oss-security/2023/10/04/1
- http://www.openwall.com/lists/oss-security/2023/10/04/2
- http://www.openwall.com/lists/oss-security/2023/10/04/4
- http://www.openwall.com/lists/oss-security/2023/10/04/3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIOYP4ZOBML4RCUM3MHRFZUQL445MZM3/
- https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
- https://security.netapp.com/advisory/ntap-20240531-0005/
- https://security.alpinelinux.org/vuln/CVE-2023-20588
- https://ubuntu.com/security/CVE-2023-20588
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7007.html
- https://git.kernel.org/linus/77245f1c3c6495521f6a3af082696ee2f8ce3921
- https://ubuntu.com/security/notices/USN-6383-1
- https://ubuntu.com/security/notices/USN-6384-1
- https://ubuntu.com/security/notices/USN-6386-1
- https://ubuntu.com/security/notices/USN-6387-1
- https://ubuntu.com/security/notices/USN-6387-2
- https://ubuntu.com/security/notices/USN-6386-2
- https://ubuntu.com/security/notices/USN-6386-3
- https://ubuntu.com/security/notices/USN-6466-1
- https://ubuntu.com/security/notices/USN-6577-1
- https://ubuntu.com/security/notices/USN-6602-1
- https://ubuntu.com/security/notices/USN-6604-1
- https://ubuntu.com/security/notices/USN-6604-2
- https://www.cve.org/CVERecord?id=CVE-2023-20588
- https://security-tracker.debian.org/tracker/CVE-2023-20588