CVE-2022-38090Insecure Storage of Sensitive Information in Intel-microcode

Severity
4.4MEDIUMNVD
OSV6.8
EPSS
0.0%
top 87.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16
Latest updateFeb 27

Description

Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20230214.1 (bookworm)

🔴Vulnerability Details

3
OSV
intel-microcode vulnerabilities2023-02-27
GHSA
GHSA-p6jp-vhc2-xhh9: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potent2023-02-16
OSV
CVE-2022-38090: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potent2023-02-16

📋Vendor Advisories

3
Ubuntu
Intel Microcode vulnerabilities2023-02-27
Red Hat
kernel: Intel firmware update for improper isolation of shared resources2023-02-16
Debian
CVE-2022-38090: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors when using In...2022