CVE-2023-20519: Use After Free
A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20519?
CVE-2023-20519 is a Use-After-Free vulnerability in the management of an SNP guest context page, which may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
What software is affected by CVE-2023-20519?
The affected software includes Amd Milanpi Firmware versions up to and excluding 1.0.0.a, and Amd Genoapi Firmware versions up to and excluding 1.0.0.3.
What is the severity of CVE-2023-20519?
CVE-2023-20519 has a severity rating of low, with a CVSS score of 3.3.
How can a malicious hypervisor exploit CVE-2023-20519?
A malicious hypervisor can exploit CVE-2023-20519 by masquerading as the guest's migration agent and potentially compromising the integrity of the guest.
Is Amd Milanpi and Amd Genoapi vulnerable to CVE-2023-20519?
Amd Milanpi and Amd Genoapi are not vulnerable to CVE-2023-20519.