CVE-2020-0549
published 2020-01-28CVE-2020-0549: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.59%
44.1th percentile
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20200609.1 (bookworm) | intel-microcode 3.20200609.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| intel | intel_processors | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cg7-p7mp-2hcx: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure
ghsa_unreviewed·2022-05-24
CVE-2020-0549 [LOW] CWE-200 GHSA-3cg7-p7mp-2hcx: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
OSV
intel-microcode regression
osv·2020-06-10·CVSS 5.5
[MEDIUM] intel-microcode regression
intel-microcode regression
USN-4385-1 provided updated Intel Processor Microcode. Unfortunately,
that update prevented certain processors in the Intel Skylake family
(06_4EH) from booting successfully. Additonally, on Ubuntu 20.04
LTS, late loading of microcode was enabled, which could lead to
system instability. This update reverts the microcode update for
the Skylake processor family and disables the late loading option on
Ubuntu 20.04 LTS.
Please note that the 'dis_ucode_ldr' kernel command line option can be
added in the boot menu to disable microcode loading for system recovery.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read o
OSV
intel-microcode vulnerabilities
osv·2020-06-09·CVSS 5.5
CVE-2020-0543 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
It was discovered that on some Intel processors, partial data values
previously read from a vector register on a physical core may be propagated
into unused portions of the store buffer. A local attacker could possible
use this to expose sensitive information. (CVE-2020-0548)
It was discovered that on some Intel processors, data from the most
recently evicted modified L1 data cache (L1D) line may be propagated in
OSV
CVE-2020-0549: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure
osv·2020-01-28·CVSS 5.5
CVE-2020-0549 [MEDIUM] CVE-2020-0549: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode regression
vendor_ubuntu·2020-06-10·CVSS 5.5
[MEDIUM] Intel Microcode regression
Title: Intel Microcode regression
Summary: USN-4385-1 introduced a regression in the Intel Microcode for some processors.
USN-4385-1 provided updated Intel Processor Microcode. Unfortunately,
that update prevented certain processors in the Intel Skylake family
(06_4EH) from booting successfully. Additonally, on Ubuntu 20.04
LTS, late loading of microcode was enabled, which could lead to
system instability. This update reverts the microcode update for
the Skylake processor family and disables the late loading option on
Ubuntu 20.04 LTS.
Please note that the 'dis_ucode_ldr' kernel command line option can be
added in the boot menu to disable microcode loading for system recovery.
We apologize for the inconvenience.
Original advisory details:
It was discovered that memory contents previo
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2020-06-09·CVSS 5.5
CVE-2020-0543 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
It was discovered that on some Intel processors, partial data values
previously read from a vector register on a physical core may be propagated
into unused portions of the store buffer. A local attacker could possible
use this to expose sensitive information. (CVE-2020-0548)
It was discovered that on some Intel processors, data from the most
Red Hat
hw: L1D Cache Eviction Sampling
vendor_redhat·2020-01-27·CVSS 5.5
CVE-2020-0549 [MEDIUM] CWE-203 hw: L1D Cache Eviction Sampling
hw: L1D Cache Eviction Sampling
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A microarchitectural timing flaw was found on some Intel processors. A corner case exists where data in-flight during the eviction process can end up in the “fill buffers” and not properly cleared by the MDS mitigations. The fill buffer contents (which were expected to be blank) can be inferred using MDS or TAA style attack methods to allow a local attacker to infer fill buffer values.
Package: microcode_ctl (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2020-0549: intel-microcode - Cleanup errors in some data cache evictions for some Intel(R) Processors may all...
vendor_debian·2020·CVSS 5.5
CVE-2020-0549 [MEDIUM] CVE-2020-0549: intel-microcode - Cleanup errors in some data cache evictions for some Intel(R) Processors may all...
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20200609.1)
bullseye: resolved (fixed in 3.20200609.1)
forky: resolved (fixed in 3.20200609.1)
sid: resolved (fixed in 3.20200609.1)
trixie: resolved (fixed in 3.20200609.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-0549 microcode_ctl: hw: L1D Cache Eviction Sampling [fedora-all]
bugzilla·2020-01-27·CVSS 5.5
CVE-2020-0549 [MEDIUM] CVE-2020-0549 microcode_ctl: hw: L1D Cache Eviction Sampling [fedora-all]
CVE-2020-0549 microcode_ctl: hw: L1D Cache Eviction Sampling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2020-0549 hw: L1D Cache Eviction Sampling
bugzilla·2020-01-08·CVSS 5.5
CVE-2020-0549 [MEDIUM] CVE-2020-0549 hw: L1D Cache Eviction Sampling
CVE-2020-0549 hw: L1D Cache Eviction Sampling
A flaw was found during cache eviction on some Intel processors which may allow a local attacker to infer cache contents and disclose information through this side-channel.
Reference:
-> https://access.redhat.com/solutions/l1d-cache-eviction-and-vector-register-sampling
Additional information:
-> https://en.wikipedia.org/wiki/Vector_processor
-> https://software.intel.com/en-us/articles/introduction-to-intel-advanced-vector-extensions
Discussion:
Created microcode_ctl tracking bugs for this issue:
Affects: fedora-all [bug 1795349]
---
References:
https://software.intel.com/security-software-guidance/software-guidance/l1d-eviction-sampling
Whitepaper:
https://cacheoutattack.com/CacheOut.pdf
---
External References:
https://access.
arXiv
CacheOut: Leaking Data on Intel CPUs via Cache Evictions
arxiv_fulltext·2020-06-23
CacheOut: Leaking Data on Intel CPUs via Cache Evictions
: Leaking Data on Intel CPUs
via Cache Evictions
utils
@IEEEauthorhalign
@IEEEauthorhalign
Stephan van Schaik*
University of Michigan
[email protected]
Marina Minkin
University of Michigan
[email protected]
Andrew Kwong
University of Michigan
[email protected]
Daniel Genkin
University of Michigan
[email protected]
Yuval Yarom
University of Adelaide and Data61
[email protected]
## Abstract
Recent transient-execution attacks, such as RIDL, Fallout, and ZombieLoad, demonstrated that attackers can leak information while it transits through microarchitectural buffers.
Named Microarchitectural Data Sampling (MDS) by Intel, these attacks are likened to ``drinking from the firehose'', as the attacker has little control over what data is observed and from what origin.
Unable
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10318https://lists.debian.org/debian-lts-announce/2020/06/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DT2VKDMQ3I37NBNJ256A2EXR7OJHXXKZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/https://security.netapp.com/advisory/ntap-20200210-0004/https://usn.ubuntu.com/4385-1/https://www.debian.org/security/2020/dsa-4701https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00016.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10318https://lists.debian.org/debian-lts-announce/2020/06/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DT2VKDMQ3I37NBNJ256A2EXR7OJHXXKZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/https://security.netapp.com/advisory/ntap-20200210-0004/https://usn.ubuntu.com/4385-1/https://www.debian.org/security/2020/dsa-4701https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.html
2020-01-28
Published