CVE-2021-33120
published 2022-02-09CVE-2021-33120: Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUINSUCLINAL
EPSS
1.02%
59.4th percentile
Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20220207.1 (bookworm) | intel-microcode 3.20220207.1 (bookworm) |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Intel Microcode vulnerabilities
osv·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Intel Microcode vulnerabilities
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on multi-core shared buffers. A local attacker could
possibly use this to ex
OSV
intel-microcode vulnerabilities
osv·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local attacker could use this to obtain
sensitive information. (CVE-2021-33117)
GHSA
GHSA-43wc-84x4-9vfc: Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to po
ghsa_unreviewed·2022-02-11
CVE-2021-33120 [MEDIUM] CWE-125 GHSA-43wc-84x4-9vfc: Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to po
Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
OSV
CVE-2021-33120: Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to po
osv·2022-02-09·CVSS 5.4
CVE-2021-33120 [MEDIUM] CVE-2021-33120: Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to po
Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-07-28·CVSS 5.5
CVE-2021-0145 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service (system crash). (CVE-2021-0127)
It was discovered that some Intel processors did not completely perform
cleanup actions on m
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2022-06-20·CVSS 5.5
CVE-2021-0127 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some Intel processors did not implement sufficient
control flow management. A local attacker could use this to cause a denial
of service. (CVE-2021-0127)
Joseph Nuzman discovered that some Intel processors did not properly
initialise shared resources. A local attacker could use this to obtain
sensitive information. (CVE-2021-0145)
Mark Ermolov, Dmitry Sklyarov and Maxim Goryachy discovered that some Intel
processors did not prevent test and debug logic from being activated at
runtime. A local attacker could use this to escalate
privileges. (CVE-2021-0146)
It was discovered that some Intel processors did not properly restrict
access in some situations. A local a
Red Hat
microcode: Out of bounds read for some Intel Atom processors
vendor_redhat·2022-02-08·CVSS 5.4
CVE-2021-33120 [MEDIUM] CWE-125 microcode: Out of bounds read for some Intel Atom processors
microcode: Out of bounds read for some Intel Atom processors
Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
A flaw was found in microcode. An out-of-bounds read under a complex microarchitectural condition in the memory subsystem for some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure or cause a denial of service via network access.
Statement: Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included change
Debian
CVE-2021-33120: intel-microcode - Out of bounds read under complex microarchitectural condition in memory subsyste...
vendor_debian·2021·CVSS 5.4
CVE-2021-33120 [MEDIUM] CVE-2021-33120: intel-microcode - Out of bounds read under complex microarchitectural condition in memory subsyste...
Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
Scope: local
bookworm: resolved (fixed in 3.20220207.1)
bullseye: resolved (fixed in 3.20220207.1~deb11u1)
forky: resolved (fixed in 3.20220207.1)
sid: resolved (fixed in 3.20220207.1)
trixie: resolved (fixed in 3.20220207.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published