Описание
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
A vulnerability was found in Intel's implementation of RAPL (Running Average Power Limit). An attacker with a local account could query the power management functionality to intelligently infer SGX enclave computation values by measuring power usage in the RAPL subsystem.
Меры по смягчению последствий
Until a firmware update and reboot can be applied, the attack vector can be reduced by limiting read access to the sysfs attributes that export this functionality to userspace.
The command:
Will do this for the current boot, it will need to be scripted to run at each boot to remain persistent across reboots.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | microcode_ctl | Not affected | ||
Red Hat Enterprise Linux 6 | microcode_ctl | Not affected | ||
Red Hat Enterprise Linux 7 | microcode_ctl | Fixed | RHSA-2020:5083 | 11.11.2020 |
Red Hat Enterprise Linux 7 | microcode_ctl | Fixed | RHSA-2021:3028 | 09.08.2021 |
Red Hat Enterprise Linux 7.2 Advanced Update Support | microcode_ctl | Fixed | RHSA-2020:5188 | 23.11.2020 |
Red Hat Enterprise Linux 7.2 Advanced Update Support | microcode_ctl | Fixed | RHSA-2021:3323 | 31.08.2021 |
Red Hat Enterprise Linux 7.3 Advanced Update Support | microcode_ctl | Fixed | RHSA-2020:5183 | 23.11.2020 |
Red Hat Enterprise Linux 7.3 Advanced Update Support | microcode_ctl | Fixed | RHSA-2021:3322 | 31.08.2021 |
Red Hat Enterprise Linux 7.3 Telco Extended Update Support | microcode_ctl | Fixed | RHSA-2020:5183 | 23.11.2020 |
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | microcode_ctl | Fixed | RHSA-2020:5183 | 23.11.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.1 Medium
CVSS3
Связанные уязвимости
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Observable discrepancy in the RAPL interface for some Intel(R) Process ...
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Уязвимость интерфейса RAPL процессоров Intel, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.1 Medium
CVSS3