CVE-2023-39368
published 2024-03-14CVE-2023-39368: Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.75%
50.8th percentile
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20240312.1~deb12u1 (bookworm) | intel-microcode 3.20240312.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2024-05-29·CVSS 6.1
CVE-2023-22655 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 16.04 LTS. (CVE-2023-28746)
It
OSV
CVE-2023-39368: Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of serv
osv·2024-03-14·CVSS 6.5
CVE-2023-39368 [MEDIUM] CVE-2023-39368: Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of serv
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.
GHSA
GHSA-pvrq-gg3w-f695: Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of serv
ghsa_unreviewed·2024-03-14
CVE-2023-39368 [MEDIUM] CWE-693 GHSA-pvrq-gg3w-f695: Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of serv
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-05-29·CVSS 6.1
CVE-2023-46103 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubunt
Red Hat
kernel: Possible Denial of Service on Intel(R) Processors
vendor_redhat·2024-02-14·CVSS 6.5
CVE-2023-39368 [MEDIUM] CWE-693 kernel: Possible Denial of Service on Intel(R) Processors
kernel: Possible Denial of Service on Intel(R) Processors
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.
A vulnerability was found in the bus lock regulator mechanism for some Intel processors models. This issue may allow a malicious actor to achieve a Denial of Service attack, impacting the system availability of the targeted host.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 6) - Not affected
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package:
Debian
CVE-2023-39368: intel-microcode - Protection mechanism failure of bus lock regulator for some Intel(R) Processors ...
vendor_debian·2023·CVSS 6.5
CVE-2023-39368 [MEDIUM] CVE-2023-39368: intel-microcode - Protection mechanism failure of bus lock regulator for some Intel(R) Processors ...
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky: resolved (fixed in 3.20240312.1)
sid: resolved (fixed in 3.20240312.1)
trixie: resolved (fixed in 3.20240312.1)
No detection rules found.
No public exploits indexed.
https://lists.debian.org/debian-lts-announce/2024/05/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20240405-0007/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00972.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20240405-0007/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00972.html
2024-03-14
Published