First published: Tue Jun 25 2019(Updated: )
Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/amd64-microcode | <=3.20181128.1 | 3.20230719.1~deb10u1 3.20230808.1.1~deb11u1 3.20230719.1~deb11u1 3.20230808.1.1~deb12u1 3.20230719.1~deb12u1 3.20231019.1 |
Amd Secure Encrypted Virtualization Firmware | <=0.17b11 | |
Amd Epyc 7251 | ||
Amd Epyc 7261 | ||
Amd Epyc 7281 | ||
Amd Epyc 7301 | ||
Amd Epyc 7351 | ||
Amd Epyc 7351p | ||
Amd Epyc 7371 | ||
Amd Epyc 7401 | ||
Amd Epyc 7401p | ||
Amd Epyc 7451 | ||
Amd Epyc 7501 | ||
Amd Epyc 7551 | ||
Amd Epyc 7551p | ||
Amd Epyc 7601 | ||
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9836 is a vulnerability in the Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP) that has an insecure cryptographic implementation.
CVE-2019-9836 has a severity rating of 5.3, which is classified as medium.
CVE-2019-9836 affects Amd Secure Encrypted Virtualization Firmware version 0.17 build 11 and earlier.
To fix CVE-2019-9836, update the Amd Secure Encrypted Virtualization Firmware to version 0.17 build 12 or later.
You can find more information about CVE-2019-9836 on the following references: [link1](https://seclists.org/fulldisclosure/2019/Jun/46), [link2](https://security-tracker.debian.org/tracker/CVE-2019-9836), [link3](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00032.html).