Privileged Attacker May Access Stale Data from Other Guests via Failure to Initialize Memory
CVE-2023-31346
Key Information:
- Vendor
Amd
- Vendor
- CVE Published:
- 13 February 2024
What is CVE-2023-31346?
A vulnerability in AMD's SEV Firmware stems from a failure to properly initialize memory, creating a risk where a privileged attacker can access outdated data belonging to other virtual guests. This issue presents significant security implications for environments utilizing virtualization, as it may compromise the confidentiality of sensitive information processed by other users. Users of affected AMD SEV Firmware must prioritize remediation efforts to safeguard their virtualized workloads.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
3rd Gen AMD EPYC™ Processors x86 various
4th Gen AMD EPYC™ Processors x86 various
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved