CVE-2023-31364 describes an improper handling of direct memory writes within the input-output memory management unit, allowing a malicious guest VM to flood a host with writes, potentially causing a denial of service via a fatal machine check error. This vulnerability has a high CVSS score of 8.3, indicating a significant impact on availability with low attack complexity and no user interaction required. There is currently no public exploit intelligence available, it is not listed in CISA's KEV catalog, and community discussion is minimal, with only one mention identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | AMD Athlon™ 3000 Series Mobile Processors With Radeon™ Graphics | No Fix PlannedCNA affecteddefault affected | |
| AMD | AMD EPYC™ 7001 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 7002 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 7003 Series Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 8004 Series Processors | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.