A vulnerability tracked as CVE-2023-46813 affects the Linux kernel's handling of AMD Secure Encrypted Virtualization (SEV) guests. A low-privileged local user in an SEV virtual machine can use MMIO/string I/O exception-emulation paths to trigger a buffer overflow or null-pointer dereference, potentially causing a denial of service or escalating privileges. Red Hat rates the issue CVSS 7.0 and categorizes it as improper privilege management (CWE-269).
Linux fixed the flaw by adding validation in the x86 SEV exception-emulation code before string I/O reads and writes. The new vc_insn_string_check() rejects user-space I/O operations whose addresses point into kernel space and raises a user page fault instead. Red Hat issued fixes for affected RHEL 8 and RHEL 9 kernel variants and Red Hat Virtualization 4 on RHEL 8; it reported no generally suitable mitigation beyond applying the relevant updates.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:0897 and RHSA-2024:0881, fixing CVE-2023-46813 in the RHEL 8 kernel and kernel-rt packages.
Red Hat issued RHSA-2024:0724 to fix the flaw in the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Red Hat addressed CVE-2023-46813 in the RHEL 8.8 Extended Update Support kernel through RHSA-2024:0575.
Red Hat issued fixes for the RHEL 9 kernel, RHEL 9.0 EUS kernel and kernel-rt, and RHEL 9.2 EUS kernel and kernel-rt through RHSA-2024:0461, RHSA-2024:0432, RHSA-2024:0431, RHSA-2024:0448, and RHSA-2024:0439.
CVE-2023-46813, a Linux kernel AMD SEV flaw involving a buffer overflow and null-pointer dereference triggered through MMIO-register access from an SEV guest, was made public. A low-privileged local attacker could crash the system or escalate privileges.
The Linux kernel added checks to its x86 SEV exception-emulation path to reject user-mode string I/O operations targeting kernel-space addresses, raising a user page fault instead of continuing the access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.