CVE-2023-38575
published 2024-03-14CVE-2023-38575: Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.27%
18.9th percentile
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20240312.1~deb12u1 (bookworm) | intel-microcode 3.20240312.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2024-05-29·CVSS 6.1
CVE-2023-22655 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 16.04 LTS. (CVE-2023-28746)
It
GHSA
GHSA-x28p-h97m-3347: Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable in
ghsa_unreviewed·2024-03-14
CVE-2023-38575 [MEDIUM] CWE-1303 GHSA-x28p-h97m-3347: Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable in
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
OSV
CVE-2023-38575: Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable in
osv·2024-03-14·CVSS 5.5
CVE-2023-38575 [MEDIUM] CVE-2023-38575: Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable in
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-05-29·CVSS 6.1
CVE-2023-46103 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubunt
Red Hat
kernel: Local information disclosure in some Intel(R) processors
vendor_redhat·2024-02-14·CVSS 5.5
CVE-2023-38575 [MEDIUM] CWE-1303 kernel: Local information disclosure in some Intel(R) processors
kernel: Local information disclosure in some Intel(R) processors
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
A vulnerability was found in some Intel processors that may allow a malicious actor to achieve a local information disclosure, impacting the data confidentiality of the targeted host.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 6) - Not affected
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: microcode_ctl (Red Hat E
Debian
CVE-2023-38575: intel-microcode - Non-transparent sharing of return predictor targets between contexts in some Int...
vendor_debian·2023·CVSS 5.5
CVE-2023-38575 [MEDIUM] CVE-2023-38575: intel-microcode - Non-transparent sharing of return predictor targets between contexts in some Int...
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky: resolved (fixed in 3.20240312.1)
sid: resolved (fixed in 3.20240312.1)
trixie: resolved (fixed in 3.20240312.1)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
blogs_bleepingcomputer·2024-10-18·CVSS 5.5
[MEDIUM] Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
## Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
## Bill Toulas
Speculative execution is a performance optimization feature on modern CPUs that executes instructions before knowing if they are needed by future tasks, thus speeding up the process when the prediction is correct. Instructions executed based on the misprediction are called transient and are squashed.
This mechanism has been a source of side-channel risks, such as Spectre , because the speculation process calls sensitive data that could be retrieved from the CPU cache.
## New Spectre-like attacks
ETH Zurich researchers Johannes Wikner and Kaveh Razavi explain that despite the multi-year mitigation effort to contain Spectre-like attacks, there have been numerous variants that bypass existing defenses.
Bugzilla
CVE-2023-38575 kernel: Local information disclosure in some Intel(R) processors
bugzilla·2024-03-21·CVSS 5.5
CVE-2023-38575 [MEDIUM] CVE-2023-38575 kernel: Local information disclosure in some Intel(R) processors
CVE-2023-38575 kernel: Local information disclosure in some Intel(R) processors
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00982.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2270735]
---
"Intel is releasing a firmware update to mitigate this potential vulnerability."
And again, another microcode, not kernel.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9401 https://access.redhat.com/errata/RHSA-2024:9401
https://lists.debian.org/debian-lts-announce/2024/05/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20240405-0008/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00982.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20240405-0008/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00982.html
2024-03-14
Published