CWE
327
Advisory Published
Updated

CVE-2019-9836

First published: Tue Jun 25 2019(Updated: )

Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
debian/amd64-microcode<=3.20181128.1
3.20230719.1~deb10u1
3.20230808.1.1~deb11u1
3.20230719.1~deb11u1
3.20230808.1.1~deb12u1
3.20230719.1~deb12u1
3.20231019.1
Amd Secure Encrypted Virtualization Firmware<=0.17b11
Amd Epyc 7251
Amd Epyc 7261
Amd Epyc 7281
Amd Epyc 7301
Amd Epyc 7351
Amd Epyc 7351p
Amd Epyc 7371
Amd Epyc 7401
Amd Epyc 7401p
Amd Epyc 7451
Amd Epyc 7501
Amd Epyc 7551
Amd Epyc 7551p
Amd Epyc 7601
openSUSE Leap=15.0
openSUSE Leap=15.1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2019-9836?

    CVE-2019-9836 is a vulnerability in the Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP) that has an insecure cryptographic implementation.

  • How severe is CVE-2019-9836?

    CVE-2019-9836 has a severity rating of 5.3, which is classified as medium.

  • Which software is affected by CVE-2019-9836?

    CVE-2019-9836 affects Amd Secure Encrypted Virtualization Firmware version 0.17 build 11 and earlier.

  • How can I fix CVE-2019-9836?

    To fix CVE-2019-9836, update the Amd Secure Encrypted Virtualization Firmware to version 0.17 build 12 or later.

  • Where can I find more information about CVE-2019-9836?

    You can find more information about CVE-2019-9836 on the following references: [link1](https://seclists.org/fulldisclosure/2019/Jun/46), [link2](https://security-tracker.debian.org/tracker/CVE-2019-9836), [link3](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00032.html).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203