First published: Tue Jun 25 2019(Updated: )
Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/amd64-microcode | <=3.20181128.1 | 3.20230719.1~deb10u1 3.20230808.1.1~deb11u1 3.20230719.1~deb11u1 3.20230808.1.1~deb12u1 3.20230719.1~deb12u1 3.20231019.1 |
AMD Secure Encrypted Virtualization firmware | <=0.17b11 | |
AMD EPYC 7251 Firmware | ||
AMD Epyc 7261 | ||
AMD EPYC 7281 Firmware | ||
AMD EPYC 7301 Firmware | ||
AMD EPYC 7351 Firmware | ||
AMD EPYC 7351P Firmware | ||
AMD EPYC 7371 Firmware | ||
AMD EPYC 7401 Firmware | ||
AMD EPYC 7401P Firmware | ||
AMD EPYC 7451 Firmware | ||
AMD EPYC 7501 | ||
AMD EPYC 7551 Firmware | ||
AMD EPYC 7551P Firmware | ||
AMD EPYC 7601 Firmware | ||
SUSE Linux | =15.0 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9836 is a vulnerability in the Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP) that has an insecure cryptographic implementation.
CVE-2019-9836 has a severity rating of 5.3, which is classified as medium.
CVE-2019-9836 affects Amd Secure Encrypted Virtualization Firmware version 0.17 build 11 and earlier.
To fix CVE-2019-9836, update the Amd Secure Encrypted Virtualization Firmware to version 0.17 build 12 or later.
You can find more information about CVE-2019-9836 on the following references: [link1](https://seclists.org/fulldisclosure/2019/Jun/46), [link2](https://security-tracker.debian.org/tracker/CVE-2019-9836), [link3](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00032.html).