GCP-2023-44
<strong>Published:</strong><br/><table class="fixed"> <thead> <tr> <th width="70%">Description</th> <th>Severity</th> <th>Notes</th> </tr> </thead> <tbody> <tr> <td> <p>On November 14, AMD disclosed multiple vulnerabilities that impact various AMD server CPUs. Specifically, the vulnerabilities impact EPYC Server CPUs leveraging Zen core generation 2 "Rome," gen 3 "Milan," and gen 4 "Genoa."</p> <p>Google has applied fixes to affected assets, including Google Cloud, to ensure customers are protected. At this time, no evidence of exploitation has been found or reported to Google. </p> <h4 data-text="What should I do?" id="what-should-i-do_16" tabindex="-1">What should I do?</h4> <p>No customer action is required.</p> <p>Fixes have already been applied to the Google server fleet for Google Cloud, including Google Compute Engine. </p> <h4 data-text="What vulnerabilities are addressed by this patch?" id="what-vulnerabilities-are-addressed-by-this-patch_1" tabindex="-1">What vulnerabilities are addressed by this patch?</h4> <p>The patch mitigated the following vulnerabilities:</p> <ul> <li>CVE-2022-23820</li> <li>CVE-2021-46774</li> <li>CVE-2023-20533</li> <li>CVE-2023-20519</li> <li>CVE-2023-20592</li> <li>CVE-2023-20566</li> <li>CVE-2023-20521</li> <li>CVE-2021-46766</li> <li>CVE-2022-23830</li> <li>CVE-2023-20526</li> <li>CVE-2021-26345</li> </ul> <p>For more information, see AMD's security advisory <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3005.html">AMD-SN-3005: "AMD INVD Instruction Security Notice"</a>, also published as CacheWarp, and <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3002.html">AMD-SN-3002: "AMD Server Vulnerabilities – November 2023"</a>.</p> </td> <td> Medium </td> <td> <ul> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23820" target="mitre">CVE-2022-23820</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-46774" target="mitre">CVE-2021-46774</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20533" target="mitre">CVE-2023-20533</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20519" target="mitre">CVE-2023-20519</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20592" target="mitre">CVE-2023-20592</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20566" target="mitre">CVE-2023-20566</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23830" target="mitre">CVE-2022-23830</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20526" target="mitre">CVE-2023-20526</a></li> <li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-26345" target="mitre">CVE-2021-26345</a></li> </ul> </td> </tr> </tbody> </table>
Timeline
- Apr 14, 2026 CVE Published
References
- GCP-2023-44 (Medium) advisory
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3005.html web
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3002.html web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23820 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-46774 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20533 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20519 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20592 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20566 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23830 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20526 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-26345 web