Описание
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A flaw was found in Intel processors where a local attacker is able to gain information about registers used for vector calculations by observing register states from other processes running on the system. This results in a race condition where store buffers, which were not cleared, could be read by another process or a CPU sibling. The highest threat from this vulnerability is data confidentiality where an attacker could read arbitrary data as it passes through the processor.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | microcode_ctl | Out of support scope | ||
Red Hat Enterprise Linux 6 | microcode_ctl | Fixed | RHSA-2020:2433 | 09.06.2020 |
Red Hat Enterprise Linux 6.5 Advanced Update Support | microcode_ctl | Fixed | RHSA-2020:2707 | 23.06.2020 |
Red Hat Enterprise Linux 6.6 Advanced Update Support | microcode_ctl | Fixed | RHSA-2020:2706 | 23.06.2020 |
Red Hat Enterprise Linux 7 | microcode_ctl | Fixed | RHSA-2020:2432 | 10.06.2020 |
Red Hat Enterprise Linux 7 | microcode_ctl | Fixed | RHSA-2021:3028 | 09.08.2021 |
Red Hat Enterprise Linux 7.2 Advanced Update Support | microcode_ctl | Fixed | RHSA-2020:2679 | 23.06.2020 |
Red Hat Enterprise Linux 7.2 Advanced Update Support | microcode_ctl | Fixed | RHSA-2021:3323 | 31.08.2021 |
Red Hat Enterprise Linux 7.3 Advanced Update Support | microcode_ctl | Fixed | RHSA-2020:2680 | 23.06.2020 |
Red Hat Enterprise Linux 7.3 Advanced Update Support | microcode_ctl | Fixed | RHSA-2021:3322 | 31.08.2021 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
2.8 Low
CVSS3
Связанные уязвимости
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Cleanup errors in some Intel(R) Processors may allow an authenticated ...
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Уязвимость процессоров Intel, связанная с утечкой в буфер хранения (Store Buffer) результатов операций чтения из векторных регистров, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
2.8 Low
CVSS3