Summary
It was discovered that some AMD processors did not properly perform Reverse Map Table (RMP) checks when the IOMMU accessed certain host buffers. A local attacker with hypervisor access could possibly use this to trigger an out-of-bounds condition and compromise the integrity of SEV-SNP guest memory. (CVE-2023-20585)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
- ARM64 architecture;
- NVDIMM (Non-Volatile Memory Device) drivers;
- Handshake API;
- ARM32 architecture;
- MIPS architecture;
- OpenRISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Compute Acceleration Framework;
- Intel NPU Driver;
- ACPI drivers;
- Android drivers;
- Serial ATA and Parallel ATA drivers;
- Drivers core;
- Rados block device (RBD) driver;
- Ublk userspace block driver;
- Bluetooth drivers;
- Cdrom driver;
- Character device driver;
- TPM device driver;
- Data acquisition framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- DAX dirext access to differentiated memory framework;
- DIBS (Direct Internal Buffer Sharing) drivers;
- Buffer Sharing and Synchronization framework;
- DMA engine subsystem;
- DPLL subsystem;
- EDAC drivers;
- FireWire subsystem;
- Arm Firmware Framework for ARMv8-A(FFA);
- ARM SCMI message protocol;
- Intel Stratix 10 firmware drivers;
- FPGA Framework;
- GPIB drivers;
- GPIO subsystem;
- GPU drivers;
- HID subsystem;
- Microsoft Hyper-V drivers;
- Hardware monitoring drivers;
- CoreSight HW tracing drivers;
- Intel Trace Hub HW tracing drivers;
- I2C subsystem;
- I3C subsystem;
- IIO subsystem;
- IIO ADC drivers;
- IIO Magnetometer sensors drivers;
- InfiniBand drivers;
- Input Device (Miscellaneous) drivers;
- IOMMU subsystem;
- IRQ chip drivers;
- LED subsystem;
- Mailbox framework;
- Multiple devices driver;
- Media drivers;
- MemoryStick subsystem;
- Multifunction device drivers;
- Intel Management Engine Interface driver;
- Amazon Nitro Secure Module driver;
- MMC subsystem;
- MTD block device drivers;
- Network drivers;
- Ethernet bonding driver;
- Mellanox network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Texas Instruments network drivers;
- MediaTek network drivers;
- NTB driver;
- NVME drivers;
- Device tree and open firmware driver;
- Operating Performance Points (OPP) driver;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- i.MX PM domains;
- MediaTek PM domains;
- Power supply drivers;
- PTP clock framework;
- RapidIO drivers;
- Voltage and Current Regulator drivers;
- Remote Processor subsystem;
- MPAM driver;
- Reset controller framework;
- Real Time Clock drivers;
- S/390 drivers;
- SCSI subsystem;
- Xilinx SoC drivers;
- SoundWire subsystem;
- SPI subsystem;
- Media staging drivers;
- Media Oriented Systems Transport (MOST) driver;
- NVIDIA Tegra embedded controller (NVEC) staging driver;
- Realtek RTL8723BS SDIO drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Host Controller drivers;
- USB Dual Role (OTG-ready) Controller drivers;
- USB Serial drivers;
- vDPA drivers;
- VFIO drivers;
- Virtio Host (VHOST) subsystem;
- Framebuffer layer;
- Virtio drivers;
- Watchdog drivers;
- Xen hypervisor drivers;
- 9P distributed file system;
- AFS file system;
- File systems infrastructure;
- BTRFS file system;
- Ceph distributed file system;
- Ext4 file system;
- F2FS file system;
- FUSE (File system in Userspace);
- Journaling layer for block devices (JBD2);
- Network file systems library;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- NTFS3 file system;
- OCFS2 file system;
- Overlay file system;
- Proc file system;
- SMB network file system;
- BPF subsystem;
- File system encryption (fscrypt);
- MAC80211 subsystem;
- Live Update Orchestrator (LUO);
- Mellanox drivers;
- Networking core;
- Memory Management;
- Media input infrastructure;
- IPv6 networking;
- Bluetooth subsystem;
- Wireless networking;
- IPv4 networking;
- Netfilter;
- Network traffic control;
- SCTP protocol;
- TCP network protocol;
- XFRM subsystem;
- RDMA verbs API;
- User-space API (UAPI);
- Audit subsystem;
- Control group (cgroup);
- Kernel CPU control infrastructure;
- Kernel exit() syscall;
- Kernel fork() syscall;
- Kexec HandOver (KHO);
- Scheduler infrastructure;
- Signal handling mechanism;
- Timer subsystem;
- Tracing infrastructure;
- Codetag library;
- Resizable hashtable library;
- Memory management;
- 9P file system network protocol;
- Asynchronous Transfer Mode (ATM) subsystem;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- CAN network layer;
- Ceph Core library;
- HSR network protocol;
- IEEE802154.4 network protocol;
- IUCV driver;
- KCM (Kernel Connection Multiplexor) sockets driver;
- Logical Link layer;
- IEEE 802.15.4 subsystem;
- MultiProtocol Label Switching driver;
- Multipath TCP;
- Open vSwitch;
- Packet sockets;
- Phonet protocol;
- Packet sampling (psample);
- Qualcomm IPC Router (QRTR);
- RDS protocol;
- RxRPC session sockets;
- Sun RPC protocol;
- TIPC protocol;
- TLS protocol;
- X.25 network layer;
- AppArmor security module;
- Integrity Measurement Architecture(IMA) framework;
- Landlock security;
- SELinux security module;
- ALSA framework;
- HD-audio driver;
- AMD SoC Alsa drivers;
- Texas InstrumentS Audio (ASoC/HDA) drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- Amlogic Meson SoC drivers;
- QCOM ASoC drivers;
- SoundWire (SDCA) ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- NVIDIA Tegra ASoC drivers;
- USB sound devices;
- Perf tools;
- KVM subsystem;
View 1049 CVE identifiers
Products covered
A separate affected-products list was not included in the collected bulletin.
Remediation
This update corrects flaws in the following subsystems:
- ARM64 architecture
- NVDIMM (Non-Volatile Memory Device) drivers
- Handshake API
- ARM32 architecture
- MIPS architecture
- OpenRISC architecture
- PowerPC architecture
- RISC-V architecture
- S390 architecture
- x86 architecture
- Cryptographic API
- Compute Acceleration Framework
- Intel NPU Driver
- ACPI drivers
- Android drivers
- Serial ATA and Parallel ATA drivers
- Drivers core
- Rados block device (RBD) driver
- Ublk userspace block driver
- Bluetooth drivers
- Cdrom driver
- Character device driver
- TPM device driver
- Data acquisition framework and drivers
- Hardware crypto device drivers
- CXL (Compute Express Link) drivers
- DAX dirext access to differentiated memory framework
- DIBS (Direct I
CVEs in this advisory 1
Updates
- Published by Ubuntu
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.