Input validation error in Intel products - CVE-2021-0127

 

Input validation error in Intel products - CVE-2021-0127

Published: February 10, 2022


Vulnerability identifier: #VU60493
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0127
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient control flow management. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Intel Xeon Scalable Processors
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Intel Xeon Processor E3 v5 Family
Intel Xeon Platinum 81xxD
Intel Xeon D Processors
Intel Xeon Processor E3 v6 Family
Intel Xeon Processor E Family
Intel Xeon W Processors
3rd Generation Intel Xeon Scalable Processors
2nd Generation Intel Xeon Scalable Processors
6th Generation Intel Core Processors
Intel Pentium Gold Processor Series
Intel Core X-series Processors
Intel Celeron Processor G Series
10th Generation Intel Core Processors
8th Generation Intel Core Processors
7th Generation Intel Core Processors
VEP4600-16 Core
VEP4600-4 Core
VEP4600-8 Core
9th Generation Intel Core Processors
Gentoo Linux
F5OS
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
Ubuntu
EMC Integrated Data Protection Appliance
IBM Qradar SIEM
intel-microcode (Ubuntu package)
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
Dell EMC VxRail Appliance
Integrated System for Microsoft Azure Stack Hub

How to mitigate CVE-2021-0127

Install updates from vendor's website.

VEP4600-16 Core - update to UFW-3.8
VEP4600-4 Core - update to UFW-3.8
VEP4600-8 Core - update to UFW-3.8
intel-microcode (Ubuntu package) - addressed in versions 3.20220510.0ubuntu0.16.04.1+esm1, 3.20220510.0ubuntu0.18.04.1, 3.20220510.0ubuntu0.20.04.1, 3.20220510.0ubuntu0.21.10.1, 3.20220510.0ubuntu0.22.04.1
Dell EMC VxRail Appliance - update to 4.5.480
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Integrated System for Microsoft Azure Stack Hub - update to 2210
ucode-intel - addressed in versions 20220207-3.38.1, 20220207-3.70.1, 20220207-3.206.1, 20220207-10.1, 20220207-13.93.1
ucode-intel-debuginfo - addressed in versions 20220207-3.38.1, 20220207-13.93.1
ucode-intel-debugsource - addressed in versions 20220207-3.38.1, 20220207-13.93.1

External References

Related Security Bulletins