CVE-2023-46103
published 2024-05-16CVE-2023-46103: Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable…
PriorityP413medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.28%
19.9th percentile
Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20240514.1~deb12u1 (bookworm) | intel-microcode 3.20240514.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2024-05-29·CVSS 6.1
CVE-2023-46103 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubunt
Red Hat
intel-microcode: Unexpected behavior in Intel(R) Core(TM) Ultra Processors
vendor_redhat·2024-05-14·CVSS 4.7
CVE-2023-46103 [MEDIUM] CWE-400 intel-microcode: Unexpected behavior in Intel(R) Core(TM) Ultra Processors
intel-microcode: Unexpected behavior in Intel(R) Core(TM) Ultra Processors
Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.
A flaw was found in intel-microcode. The sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra processors that may allow an authenticated user to enable a denial of service via local access.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - N
Debian
CVE-2023-46103: intel-microcode - Sequence of processor instructions leads to unexpected behavior in Intel(R) Core...
vendor_debian·2023·CVSS 4.7
CVE-2023-46103 [MEDIUM] CVE-2023-46103: intel-microcode - Sequence of processor instructions leads to unexpected behavior in Intel(R) Core...
Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20240514.1~deb12u1)
bullseye: resolved (fixed in 3.20240514.1~deb11u1)
forky: resolved (fixed in 3.20240514.1)
sid: resolved (fixed in 3.20240514.1)
trixie: resolved (fixed in 3.20240514.1)
OSV
intel-microcode vulnerabilities
osv·2024-05-29·CVSS 6.1
CVE-2023-22655 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
It was discovered that some 3rd and 4th Generation Intel® Xeon® Processors
did not properly restrict access to certain hardware features when using
Intel® SGX or Intel® TDX. This may allow a privileged local user to
potentially further escalate their privileges on the system. This issue only
affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 16.04 LTS. (CVE-2023-22655)
It was discovered that some Intel® Atom® Processors did not properly clear
register state when performing various operations. A local attacker could
use this to obtain sensitive information via a transient execution attack.
This issue only affected Ubuntu 23.10, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 16.04 LTS. (CVE-2023-28746)
It
OSV
CVE-2023-46103: Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially e
osv·2024-05-16·CVSS 4.7
CVE-2023-46103 [MEDIUM] CVE-2023-46103: Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially e
Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.
GHSA
GHSA-xp8f-77p3-p5rv: Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially e
ghsa_unreviewed·2024-05-16
CVE-2023-46103 [MEDIUM] CWE-1281 GHSA-xp8f-77p3-p5rv: Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially e
Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-16
Published