Unrated severityNVD Advisory· Published Jun 25, 2019· Updated Aug 4, 2024
CVE-2019-9836
CVE-2019-9836
Description
Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.
Affected products
43- AMD Platform Security Processor/Secure Encrypted Virtualizationdescription
- osv-coords42 versionspkg:rpm/opensuse/kernel-firmware-all&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-amdgpu&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-ath10k&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-ath11k&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-ath12k&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-atheros&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-bluetooth&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-bnx2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-brcm&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-chelsio&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/kernel-firmware&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/kernel-firmware&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-dpaa2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-i915&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-intel&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-iwlwifi&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-liquidio&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-marvell&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-media&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-mediatek&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-mellanox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-mwifiex&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-network&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-nfp&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-nvidia&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-platform&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-prestera&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-qcom&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-qlogic&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-radeon&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-realtek&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-serial&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-sound&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-ti&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-ueagle&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-firmware-usb-network&distro=openSUSE%20Tumbleweedpkg:rpm/suse/kernel-firmware&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/kernel-firmware&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/kernel-firmware&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/kernel-firmware&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/kernel-firmware&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4
< 20250206-1.1+ 41 more
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250208-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20190618-lp151.2.6.1
- (no CPE)range: < 20190618-lp151.2.6.1
- (no CPE)range: < 20210901-1.2
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250210-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250210-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20250206-1.1
- (no CPE)range: < 20190618-5.8.1
- (no CPE)range: < 20190618-3.22.1
- (no CPE)range: < 20190618-3.3.1
- (no CPE)range: < 20190618-5.8.1
- (no CPE)range: < 20190618-5.8.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.opensuse.org/opensuse-security-announce/2019-07/msg00032.htmlmitrevendor-advisoryx_refsource_SUSE
- packetstormsecurity.com/files/153436/AMD-Secure-Encrypted-Virtualization-SEV-Key-Recovery.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2019/Jun/46mitrex_refsource_MISC
- support.hpe.com/hpsc/doc/public/displaymitrex_refsource_CONFIRM
- www.amd.com/en/corporate/product-securitymitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.