CVE-2023-20584
Linux Kernel vulnerability analysis and mitigation

Overview

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which was identified as CVE-2023-20584. This vulnerability affects AMD EPYC processors and their platform components, particularly in the context of SEV-SNP (Secure Encrypted Virtualization - Secure Nested Paging) systems. The vulnerability was disclosed in August 2024 (AMD Bulletin, Red Hat Portal).

Technical details

The vulnerability has been assigned a CVSS v3 base score of 5.3 (Medium) with the vector string CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N. The technical nature of the vulnerability involves improper handling of special address ranges with invalid device table entries in the IOMMU, which can lead to DTE faults that potentially bypass RMP (Resource Mapping Protection) checks in SEV-SNP environments (Red Hat Portal).

Impact

If successfully exploited, this vulnerability could lead to a loss of guest integrity in SEV-SNP environments. The impact is primarily focused on integrity with no direct effect on confidentiality or availability. The vulnerability requires an attacker to have privileges and a compromised Hypervisor to successfully exploit the weakness (AMD Bulletin).

Exploitability

The vulnerability requires local access (AV:L), high attack complexity (AC:H), and high privileges (PR:H) for exploitation. An attacker would need both privileges and a compromised Hypervisor to successfully exploit this vulnerability. No user interaction is required for the exploitation process (Red Hat Portal).

Mitigation and workarounds

AMD has released firmware updates to address this vulnerability. For 3rd Gen AMD EPYC processors (Milan), the fix is available in MilanPI 1.0.0.C (2023-12-18) and SEV firmware version 1.55.9. For 4th Gen AMD EPYC processors (Genoa), the fix is included in GenoaPI 1.0.0.B (2023-12-15) and SEV firmware version 1.55.23. Users are recommended to update to these firmware versions to mitigate the vulnerability (AMD Bulletin).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-89654CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-extra
NoYesSep 11, 2026
CVE-2026-89711HIGH8.2
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesSep 11, 2026
CVE-2026-89682HIGH8.1
  • Linux Kernel logoLinux Kernel
  • linux-aws-7.0
NoYesSep 11, 2026
CVE-2026-89648HIGH7.5
  • Linux Kernel logoLinux Kernel
  • linux-azure-7.0
NoYesSep 11, 2026
CVE-2026-89693HIGH7
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management