CVE-2022-38090
published 2023-02-16CVE-2022-38090: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially…
PriorityP414medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.25%
16.2th percentile
Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20230214.1 (bookworm) | intel-microcode 3.20230214.1 (bookworm) |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2023-02-27·CVSS 7.5
CVE-2022-33972 [HIGH] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Erik C. Bjorge discovered that some Intel(R) Atom and Intel Xeon Scalable
Processors did not properly implement access controls for out-of-band
management. This may allow a privileged network-adjacent user to potentially
escalate privileges. (CVE-2022-21216)
Cfir Cohen, Erdem Aktas, Felix Wilhelm, James Forshaw, Josh Eads, Nagaraju
Kodalapura Nagabhushana Rao, Przemyslaw Duda, Liron Shacham and Ron Anderson
discovered that some Intel(R) Xeon(R) Processors used incorrect default
permissions in some memory controller configurations when using Intel(R)
Software Guard Extensions. This may allow a privileged local user to potentially
escalate privileges. (CVE-2022-33196)
It was discovered
Red Hat
kernel: Intel firmware update for improper isolation of shared resources
vendor_redhat·2023-02-16·CVSS 6.0
CVE-2022-38090 [MEDIUM] kernel: Intel firmware update for improper isolation of shared resources
kernel: Intel firmware update for improper isolation of shared resources
Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.
A flaw was found in the Linux kernel. A potential security vulnerability in some Intel Processors with Intel Software Guard Extensions (SGX) may allow information disclosure. This flaw may allow a privileged user to enable information disclosure via local access.
Statement: Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content. In most cases, it m
Debian
CVE-2022-38090: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors when using In...
vendor_debian·2022·CVSS 6.0
CVE-2022-38090 [MEDIUM] CVE-2022-38090: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors when using In...
Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20230214.1)
bullseye: resolved (fixed in 3.20230214.1~deb11u1)
forky: resolved (fixed in 3.20230214.1)
sid: resolved (fixed in 3.20230214.1)
trixie: resolved (fixed in 3.20230214.1)
OSV
intel-microcode vulnerabilities
osv·2023-02-27·CVSS 6.8
CVE-2022-21216 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Erik C. Bjorge discovered that some Intel(R) Atom and Intel Xeon Scalable
Processors did not properly implement access controls for out-of-band
management. This may allow a privileged network-adjacent user to potentially
escalate privileges. (CVE-2022-21216)
Cfir Cohen, Erdem Aktas, Felix Wilhelm, James Forshaw, Josh Eads, Nagaraju
Kodalapura Nagabhushana Rao, Przemyslaw Duda, Liron Shacham and Ron Anderson
discovered that some Intel(R) Xeon(R) Processors used incorrect default
permissions in some memory controller configurations when using Intel(R)
Software Guard Extensions. This may allow a privileged local user to potentially
escalate privileges. (CVE-2022-33196)
It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable Processors
did not pr
GHSA
GHSA-p6jp-vhc2-xhh9: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potent
ghsa_unreviewed·2023-02-16
CVE-2022-38090 [MEDIUM] CWE-922 GHSA-p6jp-vhc2-xhh9: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potent
Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.
OSV
CVE-2022-38090: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potent
osv·2023-02-16·CVSS 4.4
CVE-2022-38090 [MEDIUM] CVE-2022-38090: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potent
Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-16
Published