suse · CVE-2023-31346

Quick triage

Priority: medium Published: 2024-02-15 00:14:30 UTC Updated: 2025-02-16 02:14:52 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-31346 severity moderate: SUSE including 40 source package names (iwl100-firmware-39.31.5.1-122.el8_10.1, iwl100-firmware-39.31.5.1-143.1.el9_4, …), 107 product×package rows across 39 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 7.1, … (39 product lines)): Will Not Fix 69, Fixed 38.

Description:

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

cvelogic Threat Intelligence