Information disclosure in Intel Core i7-8665U - CVE-2020-0548

 

Information disclosure in Intel Core i7-8665U - CVE-2020-0548

Published: January 28, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU24688
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0548
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to cleanup errors. A local user can gain unauthorized access to sensitive information on the system.


Affected software

Intel Core i7-8665U
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
intel-microcode (Ubuntu package)
intel-microcode (Debian package)
microcode_ctl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
microcode_ctl
Oracle VM Server for x86
PowerFlex rack
Disk Library for mainframe (DLm)
Dell EMC VxRail Appliance
Juniper Junos Space

How to mitigate CVE-2020-0548

Install updates from vendor's website.

intel-microcode (Ubuntu package) - addressed in versions 3.20200609.0ubuntu0.16.04.0, 3.20200609.0ubuntu0.18.04.0, 3.20200609.0ubuntu0.19.10.0, 3.20200609.0ubuntu0.20.04.0
intel-microcode (Debian package) - addressed in versions 3.20200609.2~deb9u1, 3.20200609.2~deb10u1
microcode_ctl (Red Hat package) - addressed in versions 1.17-33.26.el6_10, 2.1-12.30.el7_2, 2.1-12.39.el7_2, 2.1-16.42.el7_3, 2.1-22.32.el7_4, 2.1-22.41.el7_4, 2.1-47.14.el7_6, 2.1-47.23.el7_6, 2.1-53.9.el7_7, 2.1-53.18.el7_7, 2.1-73.11.el7_9, 20180807a-2.20200609.1.el8_0, 20190618-1.20200609.1.el8_1, 20190618-1.20210608.1.el8_1, 20191115-4.20200602.2.el8_2, 20191115-4.20210608.1.el8_2, 20210216-1.20210608.1.el8_4
microcode_ctl - addressed in versions 2.1-38.fc31, 2.1-38.fc32, 2.1-39.fc31, 2.1-39.fc32
PowerFlex rack - addressed in versions 3.3.8.0, 3.4.3.0, 3.5.3.1
Dell EMC VxRail Appliance - update to 4.7.515
Disk Library for mainframe (DLm) - update to 5.3.0.0
Juniper Junos Space - update to 20.3R1
microcode_ctl - addressed in versions 20191115-4.20210608.1, 20210216-1.20210608.1

External References

Related Security Bulletins