CVE-2023-4155
Description
A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an attacker manages to call the handler multiple times, they can trigger a stack overflow and cause a denial of service or potentially guest-to-host escape in kernel configurations without stack guard pages (`CONFIG_VMAP_STACK`).
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description kernel: KVM: SEV-ES / SEV-SNP VMGEXIT double fetch vulnerability Red Hat statement Red Hat Enterprise Linux 6 and 7 are not affected by this flaw, as they did not include support for KVM AMD Secure Encrypted Virtualization (SEV). Note: AMD SEV is currently provided as a Technology Preview in RHEL 8, therefore, it is unsupported for production use. For additional details seeโฆ
Description
kernel: KVM: SEV-ES / SEV-SNP VMGEXIT double fetch vulnerability
Red Hat statement
Red Hat Enterprise Linux 6 and 7 are not affected by this flaw, as they did not include support for KVM AMD Secure Encrypted Virtualization (SEV). Note: AMD SEV is currently provided as a Technology Preview in RHEL 8, therefore, it is unsupported for production use. For additional details see https://access.redhat.com/articles/4491591 and https://access.redhat.com/support/offerings/techpreview.
CVSS v3: 5.3 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-513.5.1.rt7.307.el8_9 | RHSA-2023:6901 | 2023-11-14T00:00:00Z |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | RHSA-2023:7077 | 2023-11-14T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.107.1.el8_6 | RHSA-2024:3859 | 2024-06-12T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.107.1.el8_6 | RHSA-2024:3859 | 2024-06-12T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.107.1.el8_6 | RHSA-2024:3859 | 2024-06-12T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.64.1.el8_8 | RHSA-2024:4740 | 2024-07-23T00:00:00Z |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | RHSA-2023:6583 | 2023-11-07T00:00:00Z |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-362.8.1.el9_3 | RHSA-2023:6583 | 2023-11-07T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected |
| Red Hat Enterprise Linux 7 | kernel | Not affected |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected |
Apply commands
yum update -y kernel-rt
# or:
dnf upgrade -y kernel-rt
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 6 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| โ | Affected | โ |
AlmaLinux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | kernel-doc-4.18.0-513.5.1.el8_9.noarch.rpm |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 6.4.11-1 |
| sid | Fixed | 6.4.11-1 |
| forky | Fixed | 6.4.11-1 |
| bullseye | Fixed | 0 |
| bookworm | Fixed | 6.1.52-1 |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | โ |
| 8 | Fixed | โ |
References
- https://access.redhat.com/errata/RHSA-2023:6583
- https://www.suse.com/security/cve/CVE-2023-4155.html
- https://security-tracker.debian.org/tracker/CVE-2023-4155
- https://access.redhat.com/errata/RHSA-2023:7077
- https://bugzilla.redhat.com/2024989
- https://bugzilla.redhat.com/2073091
- https://bugzilla.redhat.com/2133453
- https://bugzilla.redhat.com/2133455
- https://bugzilla.redhat.com/2139610
- https://bugzilla.redhat.com/2147356
- https://bugzilla.redhat.com/2148520
- https://bugzilla.redhat.com/2149024
- https://bugzilla.redhat.com/2151317
- https://bugzilla.redhat.com/2156322
- https://bugzilla.redhat.com/2165741
- https://bugzilla.redhat.com/2165926
- https://bugzilla.redhat.com/2168332
- https://bugzilla.redhat.com/2173403
- https://bugzilla.redhat.com/2173430
- https://bugzilla.redhat.com/2173434
- https://bugzilla.redhat.com/2173444
- https://bugzilla.redhat.com/2174400
- https://bugzilla.redhat.com/2175903
- https://bugzilla.redhat.com/2176140
- https://bugzilla.redhat.com/2177371
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.