7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): HIGH
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Improper validation in a model specific register (MSR) could allow …
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
References
- https://https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.… vendor-advisory
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html vendor-advisory
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html vendor-advisory
- https://www.darkreading.com/remote-workforce/amd-issues-updates-for-silicon-lev…
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html vendor-advisory
- https://www.darkreading.com/remote-workforce/amd-issues-updates-for-silicon-lev…
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html vendor-advisory
- https://www.darkreading.com/remote-workforce/amd-issues-updates-for-silicon-lev…
- https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CO…
- https://news.ycombinator.com/item?id=41475975
Affected products
- <Milan PI 1.0.0.D
- ==various
- ==various
- ==various
- <emgenoa.pi.1.0.0.7
- ==various
- ==various
- ==various
- ==various
- ==various
- ==various
- ==various
- ==various
- ==various
- ==various
- ==various
- <EmbGenoaPI 1.0.0.7
- ==various
- ==various
- <naples.pi.1.0.0.m
- <rome.pi.1.0.0.j
- <milan.pi.1.0.0.d
- <genoa_pi_1.0.0.c
- ==various
- ==various
- ==various
- ==various
- ==various
- <comboam5pi.1.2.0.1
- <Naples PI 1.0.0.M
- <Rome PI 1.0.0.J
- <Genoa PI 1.0.0.C
- <castlepeakwspi-swrx8.1.0.0.8
- <chagallwspi-swrx8.1.0.0.8
- <dragonrangefl1.1.0.0.3e
- ==various
- <comboam4v2pi.1.2.0.cb
- ==various
- <remembrandtpi-fp7.1.0.0.b
- <mendocinopi-ft6.1.0.0.7
- <remembrandtpi-fp7.1.0.0.b
- <castlepeakpl-sp3r3.1.0.0.b
- <DragonRangeFL1 1.0.0.3e
- ==various
- <ComboAM4v2PI 1.2.0.cb
- <ComboAM5PI 1.2.0.1
- <CastlePeakWSPI-sWRX8 1.0.0.D
- <ChagallWSPI-sWRX8 1.0.0.8
- <chagallwspi-swrx8.1.0.0.8
- <comboam5pi.1.2.0.1
- <CastlePeakPI-SP3r3 1.0.0.B
- <renoirpi-fp6.1.0.0.e
- <cezannepi-fp6.1.0.1.1
- <cezannepi-fp6
- <phoenixpi-fp8-fp7.1.1.0.3
- <ChagallWSPI-sWRX8 1.0.0.8
- <picasso-fp5.1.0.1.2
- <pollockpi-ft5.1.0.0.8
- <picasso-fp5.1.0.1.2
- <comboam4v2pi.1.2.0.cb
- <comboam4v2pi.1.2.0.cb
- ==various
- <RembrandtPI-FP7 1.0.0.B
- <MendocinoPI-FT6 1.0.0.7
- <RembrandtPI-FP7 1.0.0.B
- <ComboAM5PI 1.2.0.1
- <Picasso-FP5 1.0.1.2
- <RenoirPI-FP6 1.0.0.E
- <ComboAM4v2PI 1.2.0.cb
- <CezannePI-FP6 1.0.1.1
- <CezannePI-FP6
- <PhoenixPI-FP8-FP7 1.1.0.3
- <PollockPI-FT5 1.0.0.8
- <Picasso-FP5 1.0.1.2
- <ComboAM4v2PI 1.2.0.cb
Matching in nixpkgs
pkgs.spoofdpi
Simple and fast anti-censorship tool written in Go
-
nixos-unstable -
- nixpkgs-unstable 0.12.0
pkgs.perlPackages.PPI
Parse, Analyze and Manipulate Perl (without perl)
-
nixos-unstable -
- nixpkgs-unstable 1.277
pkgs.perl538Packages.PPI
Parse, Analyze and Manipulate Perl (without perl)
-
nixos-unstable -
- nixpkgs-unstable 1.277
pkgs.perl540Packages.PPI
Parse, Analyze and Manipulate Perl (without perl)
-
nixos-unstable -
- nixpkgs-unstable 1.277
pkgs.perlPackages.GSSAPI
Perl extension providing access to the GSSAPIv2 library
-
nixos-unstable -
- nixpkgs-unstable 0.28
pkgs.perlPackages.PDFAPI2
Create, modify, and examine PDF files
-
nixos-unstable -
- nixpkgs-unstable API2-2.045
pkgs.haskellPackages.hsPID
PID control loop
-
nixos-unstable -
- nixpkgs-unstable 0.1.2
pkgs.spirv-llvm-translator
Tool and a library for bi-directional translation between SPIR-V and LLVM IR
-
nixos-unstable -
- nixpkgs-unstable 19.1.10
pkgs.perl538Packages.GSSAPI
Perl extension providing access to the GSSAPIv2 library
-
nixos-unstable -
- nixpkgs-unstable 0.28
pkgs.perl540Packages.GSSAPI
Perl extension providing access to the GSSAPIv2 library
-
nixos-unstable -
- nixpkgs-unstable 0.28
pkgs.perlPackages.PPIxUtils
Utility functions for PPI
-
nixos-unstable -
- nixpkgs-unstable 0.003
pkgs.perl538Packages.PDFAPI2
Create, modify, and examine PDF files
-
nixos-unstable -
- nixpkgs-unstable API2-2.045
pkgs.perl540Packages.PDFAPI2
Create, modify, and examine PDF files
-
nixos-unstable -
- nixpkgs-unstable API2-2.045
pkgs.perlPackages.PPIxRegexp
Parse regular expressions
-
nixos-unstable -
- nixpkgs-unstable 0.088
pkgs.perlPackages.ProcPIDFile
Manage process id files
-
nixos-unstable -
- nixpkgs-unstable 1.29
pkgs.haskellPackages.EdisonAPI
A library of efficient, purely-functional data structures (API)
-
nixos-unstable -
- nixpkgs-unstable 1.3.3.2
pkgs.perl538Packages.PPIxUtils
Utility functions for PPI
-
nixos-unstable -
- nixpkgs-unstable 0.003
pkgs.perl540Packages.PPIxUtils
Utility functions for PPI
-
nixos-unstable -
- nixpkgs-unstable 0.003
pkgs.perlPackages.WWWTwilioAPI
Accessing Twilio's REST API with Perl
-
nixos-unstable -
- nixpkgs-unstable 0.21
pkgs.perl538Packages.PPIxRegexp
Parse regular expressions
-
nixos-unstable -
- nixpkgs-unstable 0.088
pkgs.perl540Packages.PPIxRegexp
Parse regular expressions
-
nixos-unstable -
- nixpkgs-unstable 0.088
pkgs.perlPackages.OpenAPIClient
Client for talking to an Open API powered server
-
nixos-unstable -
- nixpkgs-unstable 1.07
pkgs.perlPackages.PPIxQuoteLike
Parse Perl string literals and string-literal-like things
-
nixos-unstable -
- nixpkgs-unstable 0.023
pkgs.perlPackages.PPIxUtilities
Extensions to PPI|PPI
-
nixos-unstable -
- nixpkgs-unstable 1.001000
pkgs.perl538Packages.ProcPIDFile
Manage process id files
-
nixos-unstable -
- nixpkgs-unstable 1.29
pkgs.perl540Packages.ProcPIDFile
Manage process id files
-
nixos-unstable -
- nixpkgs-unstable 1.29
pkgs.perl538Packages.WWWTwilioAPI
Accessing Twilio's REST API with Perl
-
nixos-unstable -
- nixpkgs-unstable 0.21
pkgs.perl540Packages.WWWTwilioAPI
Accessing Twilio's REST API with Perl
-
nixos-unstable -
- nixpkgs-unstable 0.21
pkgs.perl538Packages.OpenAPIClient
Client for talking to an Open API powered server
-
nixos-unstable -
- nixpkgs-unstable 1.07
pkgs.perl538Packages.PPIxQuoteLike
Parse Perl string literals and string-literal-like things
-
nixos-unstable -
- nixpkgs-unstable 0.023
pkgs.perl538Packages.PPIxUtilities
Extensions to PPI|PPI
-
nixos-unstable -
- nixpkgs-unstable 1.001000
pkgs.perl540Packages.OpenAPIClient
Client for talking to an Open API powered server
-
nixos-unstable -
- nixpkgs-unstable 1.07
pkgs.perl540Packages.PPIxQuoteLike
Parse Perl string literals and string-literal-like things
-
nixos-unstable -
- nixpkgs-unstable 0.023
pkgs.perl540Packages.PPIxUtilities
Extensions to PPI|PPI
-
nixos-unstable -
- nixpkgs-unstable 1.001000
pkgs.perlPackages.MojoliciousPluginOpenAPI
OpenAPI / Swagger plugin for Mojolicious
-
nixos-unstable -
- nixpkgs-unstable 5.09
pkgs.perl538Packages.MojoliciousPluginOpenAPI
OpenAPI / Swagger plugin for Mojolicious
-
nixos-unstable -
- nixpkgs-unstable 5.09
pkgs.perl540Packages.MojoliciousPluginOpenAPI
OpenAPI / Swagger plugin for Mojolicious
-
nixos-unstable -
- nixpkgs-unstable 5.09
Package maintainers
-
@invokes-su Souvik Sen <nixpkgs-commits@deshaw.com>
-
@despsyched Priyanshu Tripathi <priyanshu.tripathi@deshaw.com>
-
@de11n Elliot Cameron <nixpkgs-commits@deshaw.com>
-
@stigtsp Stig Palmquist <stig@stig.io>
-
@gloaming Craig Hall <ch9871@gmail.com>