CVE-2019-11139
published 2019-11-14CVE-2019-11139: Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable…
PriorityP416medium6CVSS 3.1
AVLACLPRHUINSCCNINAH
EPSS
0.36%
27.9th percentile
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20191112.1 (bookworm) | intel-microcode 3.20191112.1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode regression
vendor_ubuntu·2019-12-04·CVSS 6.5
[MEDIUM] Intel Microcode regression
Title: Intel Microcode regression
Summary: USN-4182-2 introduced a regression in the Intel Microcode for some
Skylake processors.
USN-4182-2 provided updated Intel Processor Microcode. A regression
was discovered that caused some Skylake processors to hang after
a warm reboot. This update reverts the microcode for that specific
processor family.
We apologize for the inconvenience.
Original advisory details:
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process
Ubuntu
Intel Microcode regression
vendor_ubuntu·2019-12-04·CVSS 6.5
[MEDIUM] Intel Microcode regression
Title: Intel Microcode regression
Summary: USN-4182-1 introduced a regression in the Intel Microcode for some
Skylake processors.
USN-4182-1 provided updated Intel Processor Microcode. A regression
was discovered that caused some Skylake processors to hang after
a warm reboot. This update reverts the microcode for that specific
processor family.
We apologize for the inconvenience.
Original advisory details:
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process
Red Hat
hw: voltage modulation technical advisory
vendor_redhat·2019-11-12·CVSS 6.0
CVE-2019-11139 [MEDIUM] CWE-440 hw: voltage modulation technical advisory
hw: voltage modulation technical advisory
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
Statement: Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/solutions/2019-microcode-nov
Mitigation: As of this time there are no known mitigations. Please install relevant updated packages to address this flaw.
Package: microcode_ctl (Red Hat Enterprise Linux 5) - Will not fix
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Affected
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Affect
BSD
FreeBSD-SA-19:26.mcu: Intel CPU Microcode Update
bsd_advisories·2019-11-12·CVSS 5.6
CVE-2017-5715 [MEDIUM] FreeBSD-SA-19:26.mcu: Intel CPU Microcode Update
FreeBSD-SA-19:26.mcu Security Advisory
The FreeBSD Project
Topic: Intel CPU Microcode Update
Category: 3rd party
Module: Intel CPU microcode
Announced: 2019-11-12
Credits: Intel
Affects: All supported versions of FreeBSD running on certain
Intel CPUs.
CVE Name: CVE-2019-11135, CVE-2019-11139, CVE-2018-12126,
CVE-2018-12127, CVE-2018-12130, CVE-2018-11091,
CVE-2017-5715
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
- From time to time Intel releases new CPU microcode to address functional
issues and security vulnerabilities. Such a release is also known as a
Micro Code Update (MCU), and is a component of a broader Intel Platform
Update (IPU). FreeBSD
Ubuntu
Intel Microcode update
vendor_ubuntu·2019-11-12·CVSS 6.5
CVE-2019-11135 [MEDIUM] Intel Microcode update
Title: Intel Microcode update
Summary: Several security issues were fixed in Intel Microcode.
USN-4182-2 provided updates for Intel Microcode. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information. (CVE-2019-11135)
It was discovered that certain Intel Xeon processors did not properly
restrict
Ubuntu
Intel Microcode update
vendor_ubuntu·2019-11-12·CVSS 6.5
CVE-2019-11135 [MEDIUM] Intel Microcode update
Title: Intel Microcode update
Summary: Several security issues were fixed in Intel Microcode.
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information. (CVE-2019-11135)
It was discovered that certain Intel Xeon processors did not properly
restrict access to a voltage modulation interface. A local privileged
attacker could use this to cause a denial of service (sy
Debian
CVE-2019-11139: intel-microcode - Improper conditions check in the voltage modulation interface for some Intel(R) ...
vendor_debian·2019·CVSS 6.0
CVE-2019-11139 [MEDIUM] CVE-2019-11139: intel-microcode - Improper conditions check in the voltage modulation interface for some Intel(R) ...
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20191112.1)
bullseye: resolved (fixed in 3.20191112.1)
forky: resolved (fixed in 3.20191112.1)
sid: resolved (fixed in 3.20191112.1)
trixie: resolved (fixed in 3.20191112.1)
GHSA
GHSA-m783-749c-c739: Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially
ghsa_unreviewed·2022-05-24
CVE-2019-11139 [LOW] CWE-754 GHSA-m783-749c-c739: Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
OSV
intel-microcode regression
osv·2019-12-04·CVSS 6.5
[MEDIUM] intel-microcode regression
intel-microcode regression
USN-4182-2 provided updated Intel Processor Microcode. A regression
was discovered that caused some Skylake processors to hang after
a warm reboot. This update reverts the microcode for that specific
processor family.
We apologize for the inconvenience.
Original advisory details:
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information
OSV
intel-microcode regression
osv·2019-12-04·CVSS 6.5
[MEDIUM] intel-microcode regression
intel-microcode regression
USN-4182-1 provided updated Intel Processor Microcode. A regression
was discovered that caused some Skylake processors to hang after
a warm reboot. This update reverts the microcode for that specific
processor family.
We apologize for the inconvenience.
Original advisory details:
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information
OSV
CVE-2019-11139: Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially
osv·2019-11-14·CVSS 6.0
CVE-2019-11139 [MEDIUM] CVE-2019-11139: Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
OSV
intel-microcode update
osv·2019-11-12·CVSS 6.5
[MEDIUM] intel-microcode update
intel-microcode update
USN-4182-2 provided updates for Intel Microcode. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information. (CVE-2019-11135)
It was discovered that certain Intel Xeon processors did not properly
restrict access to a voltage modulation interface. A local privileged
attacker c
OSV
intel-microcode update
osv·2019-11-12·CVSS 6.5
[MEDIUM] intel-microcode update
intel-microcode update
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents previously stored in microarchitectural buffers to a
malicious process that is executing on the same CPU core. A local attacker
could use this to expose sensitive information. (CVE-2019-11135)
It was discovered that certain Intel Xeon processors did not properly
restrict access to a voltage modulation interface. A local privileged
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11139)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11139 microcode_ctl: hw: voltage modulation technical advisory [fedora-all]
bugzilla·2019-11-12·CVSS 6.0
CVE-2019-11139 [MEDIUM] CVE-2019-11139 microcode_ctl: hw: voltage modulation technical advisory [fedora-all]
CVE-2019-11139 microcode_ctl: hw: voltage modulation technical advisory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2019-11139 hw: voltage modulation technical advisory
bugzilla·2019-10-25·CVSS 6.0
CVE-2019-11139 [MEDIUM] CVE-2019-11139 hw: voltage modulation technical advisory
CVE-2019-11139 hw: voltage modulation technical advisory
A vulnerability in the voltage regulation unit for some Intel scalable processors may allow a denial of service may allow a local privileged user to crash the system.
The CVSSv3 score provided does by Intel does not match the above description and Red Hat would disagree this would be a DOS only under the provided score. The provided score suggests that data modification is possible but with limited information this can not be proven or disproved.
A microcode update that addresses this issue will be released.
Discussion:
Acknowledgements:
Red Hat thanks Intel for reporting this issue and collaborating on the mitigations.
---
Statement:
Red Hat Product Security is aware of this issue. Updates will be released as they become av
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00046.htmlhttps://lists.debian.org/debian-lts-announce/2019/12/msg00035.htmlhttps://seclists.org/bugtraq/2019/Dec/28https://support.f5.com/csp/article/K42433061?utm_source=f5support&%3Butm_medium=RSShttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03969en_ushttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00271.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00045.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00046.htmlhttps://lists.debian.org/debian-lts-announce/2019/12/msg00035.htmlhttps://seclists.org/bugtraq/2019/Dec/28https://support.f5.com/csp/article/K42433061?utm_source=f5support&%3Butm_medium=RSShttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03969en_ushttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00271.html
2019-11-14
Published