Information disclosure in Intel Core i7-8665U - CVE-2020-0549
Published: January 28, 2020 / Updated: July 15, 2020
Vulnerability identifier: #VU24689
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0549
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to cleanup errors in some data cache evictions. A local user can gain unauthorized access to sensitive information on the system.
Affected software
Intel Core i7-8665U
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
intel-microcode (Ubuntu package)
intel-microcode (Debian package)
microcode_ctl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
microcode_ctl
Oracle VM Server for x86
PowerFlex rack
Disk Library for mainframe (DLm)
Dell EMC VxRail Appliance
Juniper Junos Space
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
intel-microcode (Ubuntu package)
intel-microcode (Debian package)
microcode_ctl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
microcode_ctl
Oracle VM Server for x86
PowerFlex rack
Disk Library for mainframe (DLm)
Dell EMC VxRail Appliance
Juniper Junos Space
How to mitigate CVE-2020-0549
Install updates from vendor's website.
intel-microcode (Ubuntu package) - addressed in versions 3.20200609.0ubuntu0.16.04.0, 3.20200609.0ubuntu0.18.04.0, 3.20200609.0ubuntu0.19.10.0, 3.20200609.0ubuntu0.20.04.0
intel-microcode (Debian package) - addressed in versions 3.20200609.2~deb9u1, 3.20200609.2~deb10u1
microcode_ctl (Red Hat package) - addressed in versions 1.17-33.26.el6_10, 2.1-12.30.el7_2, 2.1-12.39.el7_2, 2.1-16.42.el7_3, 2.1-22.32.el7_4, 2.1-22.41.el7_4, 2.1-47.14.el7_6, 2.1-47.23.el7_6, 2.1-53.9.el7_7, 2.1-53.18.el7_7, 2.1-73.11.el7_9, 20180807a-2.20200609.1.el8_0, 20190618-1.20200609.1.el8_1, 20190618-1.20210608.1.el8_1, 20191115-4.20200602.2.el8_2, 20191115-4.20210608.1.el8_2, 20210216-1.20210608.1.el8_4
microcode_ctl - addressed in versions 2.1-38.fc31, 2.1-38.fc32, 2.1-39.fc31, 2.1-39.fc32
PowerFlex rack - addressed in versions 3.3.8.0, 3.4.3.0, 3.5.3.1
Dell EMC VxRail Appliance - update to 4.7.515
Disk Library for mainframe (DLm) - update to 5.3.0.0
Juniper Junos Space - update to 20.3R1
microcode_ctl - addressed in versions 20191115-4.20210608.1, 20210216-1.20210608.1
intel-microcode (Debian package) - addressed in versions 3.20200609.2~deb9u1, 3.20200609.2~deb10u1
microcode_ctl (Red Hat package) - addressed in versions 1.17-33.26.el6_10, 2.1-12.30.el7_2, 2.1-12.39.el7_2, 2.1-16.42.el7_3, 2.1-22.32.el7_4, 2.1-22.41.el7_4, 2.1-47.14.el7_6, 2.1-47.23.el7_6, 2.1-53.9.el7_7, 2.1-53.18.el7_7, 2.1-73.11.el7_9, 20180807a-2.20200609.1.el8_0, 20190618-1.20200609.1.el8_1, 20190618-1.20210608.1.el8_1, 20191115-4.20200602.2.el8_2, 20191115-4.20210608.1.el8_2, 20210216-1.20210608.1.el8_4
microcode_ctl - addressed in versions 2.1-38.fc31, 2.1-38.fc32, 2.1-39.fc31, 2.1-39.fc32
PowerFlex rack - addressed in versions 3.3.8.0, 3.4.3.0, 3.5.3.1
Dell EMC VxRail Appliance - update to 4.7.515
Disk Library for mainframe (DLm) - update to 5.3.0.0
Juniper Junos Space - update to 20.3R1
microcode_ctl - addressed in versions 20191115-4.20210608.1, 20210216-1.20210608.1
External References
Related Security Bulletins
- Information disclosure in some Intel Processors
- Special register buffer speculative side channel attack in Red Hat Enterprise Linux 6
- Special register buffer speculative side channel attack in Red Hat Enterprise Linux Server - TUS 8.2
- Ubuntu update for Intel Microcode
- OpenSUSE Linux update for ucode-intel
- Arch Linux update for intel-ucode
- Debian update for intel-microcode
- Red Hat Enterprise Linux 7 update for Intel microcode_ctl
- Red Hat Enterprise Linux 6 update for Intel microcode_ctl
- Red Hat Enterprise Linux 7.7 update for microcode_ctl
- Red Hat Enterprise Linux Server 8.0 update for microcode_ctl
- Red Hat Enterprise Linux 7.4 update for microcode_ctl
- RHSA-2020:2842 - Security Advisory
- Multiple vulnerabilities in Oracle VM Server
- Amazon Linux AMI update for microcode_ctl
- Multiple vulnerabilities in Juniper Junos Space
- Red Hat Enterprise Linux 8.4 update for microcode_ctl
- Red Hat Enterprise Linux 7.7 update for microcode_ctl
- Red Hat Enterprise Linux 7 update for microcode_ctl
- Red Hat Enterprise Linux 8.1 update for microcode_ctl
- Red Hat Enterprise Linux Server 7.6 update for microcode_ctl
- Red Hat Enterprise Linux Server 7.3 update for microcode_ctl
- Red Hat Enterprise Linux Server 7.2 update for microcode_ctl
- Red Hat Enterprise Linux 8.2 update for microcode_ctl
- Multiple vulnerabilities in Dell EMC Disk Library for mainframe DLm8500
- Multiple vulnerabilities in Dell VxRail Appliance
- Multiple vulnerabilities in Dell PowerFlex Rack
- Red Hat Enterprise Linux 7 update for microcode_ctl
- Anolis OS update for microcode_ctl (Anolis OS 8.4)
- Anolis OS update for microcode_ctl (Anolis OS 8.2)
- Fedora 32 update for microcode_ctl
- Fedora 31 update for microcode_ctl
- Fedora 31 update for microcode_ctl
- Fedora 32 update for microcode_ctl