• CVE-2023-20577

发布时间: 2024年2月27日

修改时间: 2024年2月27日

概要

A vulnerability was found in AMD hardware due to a heap overflow in the SMM module. This issue could allow a local unauthenticated attacker to enable writing to SPI flash to execute arbitrary code.

CVSS v3 指标

NVD openEuler
CVSS评分 0.0
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-1222 A vulnerability was found in AMD hardware due to a heap overflow in the SMM module. This issue could allow a local unauthenticated attacker to enable writing to SPI flash to execute arbitrary code. 2024年2月27日

影响产品

产品 状态
KY3.4-4A linux-firmware Unaffected
KY3.4-5A linux-firmware Unaffected
KY3.5.1 linux-firmware Unaffected
KY3.5.2 linux-firmware Unaffected