Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-0548

Опубликовано: 27 янв. 2020
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

A flaw was found in Intel processors where a local attacker is able to gain information about registers used for vector calculations by observing register states from other processes running on the system. This results in a race condition where store buffers, which were not cleared, could be read by another process or a CPU sibling. The highest threat from this vulnerability is data confidentiality where an attacker could read arbitrary data as it passes through the processor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5microcode_ctlOut of support scope
Red Hat Enterprise Linux 6microcode_ctlFixedRHSA-2020:243309.06.2020
Red Hat Enterprise Linux 6.5 Advanced Update Supportmicrocode_ctlFixedRHSA-2020:270723.06.2020
Red Hat Enterprise Linux 6.6 Advanced Update Supportmicrocode_ctlFixedRHSA-2020:270623.06.2020
Red Hat Enterprise Linux 7microcode_ctlFixedRHSA-2020:243210.06.2020
Red Hat Enterprise Linux 7microcode_ctlFixedRHSA-2021:302809.08.2021
Red Hat Enterprise Linux 7.2 Advanced Update Supportmicrocode_ctlFixedRHSA-2020:267923.06.2020
Red Hat Enterprise Linux 7.2 Advanced Update Supportmicrocode_ctlFixedRHSA-2021:332331.08.2021
Red Hat Enterprise Linux 7.3 Advanced Update Supportmicrocode_ctlFixedRHSA-2020:268023.06.2020
Red Hat Enterprise Linux 7.3 Advanced Update Supportmicrocode_ctlFixedRHSA-2021:332231.08.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-203->CWE-200

EPSS

Процентиль: 68%
0.00582
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
nvd
больше 5 лет назад

Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
debian
больше 5 лет назад

Cleanup errors in some Intel(R) Processors may allow an authenticated ...

github
около 3 лет назад

Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 4
fstec
больше 5 лет назад

Уязвимость процессоров Intel, связанная с утечкой в буфер хранения (Store Buffer) результатов операций чтения из векторных регистров, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 68%
0.00582
Низкий

2.8 Low

CVSS3