QID 355199
Date Published: 2023-05-29
QID 355199: Amazon Linux Security Advisory for kernel : ALAS2023-2023-070
2023-05-11:( CVE-2023-2019 was added to this advisory. a flaw was found in the linux kernels netdevsim device driver, within the scheduling of events.
This issue results from the improper management of a reference count.
This may allow an attacker to create a denial of service condition on the system. (
( CVE-2023-2019) amd recommends using a software mitigation for this issue, which the kernel is enabling by default.
The linux kernel will use the generic retpoline software mitigation, instead of the specialized amd one, on amd instances (*5a*).
This is done by default, and no administrator action is needed. (
( CVE-2021-26341) amd recommends using a software mitigation for this issue, which the kernel is enabling by default.
( CVE-2021-26401) non-transparent sharing of branch predictor selectors between contexts in some intel(r) processors may allow an authorized user to potentially enable information disclosure. (
( CVE-2022-0001) non-transparent sharing of branch predictor within a context in some intel(r) processors may allow an authorized user to potentially enable information disclosure via local access. (
( CVE-2022-0002) a flaw was found in the linux kernel.
The existing kvm sev api has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest vm instance in amd cpu that supports secure encrypted virtualization (sev).
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2023-2023-070 -
alas.aws.amazon.com/AL2023/ALAS-2023-070.html
CVEs related to QID 355199
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2023-070 | amazon linux 2023 |
|