CVE-2023-20588

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 
References
Link Resource
http://www.openwall.com/lists/oss-security/2023/09/25/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/4 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/5 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/7 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/25/8 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/5 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/8 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/26/9 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/09/27/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/12 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/13 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/14 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/15 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/16 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/03/9 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/10/04/4 Mailing List Third Party Advisory
http://xenbits.xen.org/xsa/advisory-439.html Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGZCACEHT6ZZZGG36QQMGROBM4FLWYJX/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DIOYP4ZOBML4RCUM3MHRFZUQL445MZM3/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJTUVYZMP6BNF342DS3W7XGOGXC6JPN5/ Mailing List
https://security.netapp.com/advisory/ntap-20240531-0005/
https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7007 Vendor Advisory
https://www.debian.org/security/2023/dsa-5480 Third Party Advisory
https://www.debian.org/security/2023/dsa-5492 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:amd:epyc_7351p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7351p:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:amd:epyc_7401p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7401p:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:amd:epyc_7551p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7551p:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:amd:epyc_7251_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7251:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:amd:epyc_7261_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7261:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:amd:epyc_7281_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7281:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:amd:epyc_7301_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7301:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:amd:epyc_7351_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7351:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:amd:epyc_7371_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7371:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:amd:epyc_7401_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7401:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:amd:epyc_7451_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7451:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:amd:epyc_7501_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7501:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:amd:epyc_7551_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7551:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:amd:epyc_7571_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7571:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:amd:epyc_7601_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7601:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:amd:ryzen_5_pro_3400g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_5_pro_3400g:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:amd:ryzen_5_3400g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_5_3400g:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:amd:ryzen_5_pro_3400ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_5_pro_3400ge:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:amd:ryzen_5_pro_3350g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_5_pro_3350g:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:amd:ryzen_5_pro_3350ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_5_pro_3350ge:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:amd:ryzen_3_pro_3200g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_pro_3200g:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:amd:ryzen_3_3200g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3200g:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:amd:ryzen_3_3200ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3200ge:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:amd:ryzen_3_pro_3200ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_pro_3200ge:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:amd:athlon_pro_300ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:athlon_pro_300ge:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:amd:athlon_gold_3150ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:athlon_gold_3150ge:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:amd:athlon_gold_pro_3150ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:athlon_gold_pro_3150ge:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:amd:athlon_gold_3150g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:athlon_gold_3150g:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:amd:athlon_gold_pro_3150g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:athlon_gold_pro_3150g:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:amd:athlon_silver_3050ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:athlon_silver_3050ge:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:amd:athlon_silver_pro_3125ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:athlon_silver_pro_3125ge:-:*:*:*:*:*:*:*

Configuration 33 (hide)

cpe:2.3:o:xen:xen:-:*:*:*:*:*:*:*

Configuration 34 (hide)

OR cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

Configuration 35 (hide)

OR cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*

History

10 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240531-0005/ -

01 Apr 2024, 15:45

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
First Time Microsoft windows Server 2022 23h2
Microsoft windows Server 2016
Microsoft windows 11 23h2
Microsoft windows 10 1607
Microsoft windows 11 21h2
Microsoft windows Server 2008
Microsoft windows 10 1507
Microsoft windows 10 21h2
Microsoft windows Server 2019
Microsoft windows Server 2012
Microsoft windows 11 22h2
Microsoft
Microsoft windows 10 1809
Microsoft windows 10 22h2

Information

Published : 2023-08-08 18:15

Updated : 2024-06-10 18:15


NVD link : CVE-2023-20588

Mitre link : CVE-2023-20588

CVE.ORG link : CVE-2023-20588


JSON object : View

Products Affected

amd

  • epyc_7601_firmware
  • epyc_7501_firmware
  • epyc_7351_firmware
  • epyc_7351
  • epyc_7551_firmware
  • athlon_pro_300ge
  • epyc_7501
  • epyc_7401
  • ryzen_5_pro_3400ge_firmware
  • ryzen_3_pro_3200g
  • epyc_7251
  • athlon_gold_3150ge
  • epyc_7451_firmware
  • epyc_7401p
  • athlon_gold_3150ge_firmware
  • epyc_7261_firmware
  • athlon_silver_3050ge_firmware
  • epyc_7261
  • athlon_silver_pro_3125ge_firmware
  • epyc_7551p_firmware
  • epyc_7601
  • ryzen_3_3200g
  • athlon_gold_pro_3150g
  • athlon_silver_3050ge
  • ryzen_5_pro_3400ge
  • epyc_7301_firmware
  • epyc_7451
  • athlon_gold_pro_3150ge
  • ryzen_5_pro_3350g_firmware
  • ryzen_5_pro_3350g
  • epyc_7571
  • athlon_gold_pro_3150ge_firmware
  • epyc_7371
  • athlon_gold_3150g_firmware
  • athlon_silver_pro_3125ge
  • ryzen_5_3400g
  • epyc_7301
  • ryzen_3_3200ge_firmware
  • epyc_7551p
  • ryzen_3_3200g_firmware
  • epyc_7401p_firmware
  • ryzen_5_pro_3400g_firmware
  • epyc_7551
  • epyc_7571_firmware
  • athlon_gold_3150g
  • epyc_7401_firmware
  • epyc_7281
  • ryzen_3_pro_3200ge
  • epyc_7251_firmware
  • ryzen_5_pro_3350ge
  • athlon_pro_300ge_firmware
  • ryzen_5_pro_3400g
  • ryzen_3_pro_3200g_firmware
  • ryzen_3_pro_3200ge_firmware
  • epyc_7371_firmware
  • epyc_7351p
  • ryzen_5_pro_3350ge_firmware
  • ryzen_5_3400g_firmware
  • epyc_7351p_firmware
  • epyc_7281_firmware
  • ryzen_3_3200ge
  • athlon_gold_pro_3150g_firmware

microsoft

  • windows_10_1507
  • windows_server_2019
  • windows_11_22h2
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_23h2
  • windows_server_2016
  • windows_11_21h2
  • windows_10_1809
  • windows_10_1607
  • windows_server_2012
  • windows_server_2008
  • windows_server_2022_23h2

debian

  • debian_linux

fedoraproject

  • fedora

xen

  • xen
CWE
CWE-369

Divide By Zero