CVE-2021-33120Out-of-bounds Read in Intel-microcode

CWE-125Out-of-bounds Read9 documents6 sources
Severity
5.4MEDIUMNVD
OSV5.5
EPSS
0.7%
top 28.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 9
Latest updateJul 28

Description

Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20220207.1 (bookworm)

🔴Vulnerability Details

4
OSV
Intel Microcode vulnerabilities2022-07-28
OSV
intel-microcode vulnerabilities2022-06-20
GHSA
GHSA-43wc-84x4-9vfc: Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to po2022-02-11
OSV
CVE-2021-33120: Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to po2022-02-09

📋Vendor Advisories

4
Ubuntu
Intel Microcode vulnerabilities2022-07-28
Ubuntu
Intel Microcode vulnerabilities2022-06-20
Red Hat
microcode: Out of bounds read for some Intel Atom processors2022-02-08
Debian
CVE-2021-33120: intel-microcode - Out of bounds read under complex microarchitectural condition in memory subsyste...2021