Security features bypass in Intel products - CVE-2021-0146
Published: June 20, 2022
Vulnerability identifier: #VU64522
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0146
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to hardware allows activation of test or debug logic at runtime. An attacker with physical access to device can execute arbitrary code with elevated privileges.
Affected software
Intel Pentium Processor J Series
Intel Pentium Processor N Series
Intel Atom Processor E3900 Series
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Intel Celeron Processor J Series
Intel Celeron Processor N Series
Intel Atom Processor A Series
Intel Pentium Processor Silver Series
Intel Atom processor C3000 series
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
microcode_ctl
intel-microcode (Ubuntu package)
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
Intel Pentium Processor N Series
Intel Atom Processor E3900 Series
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Intel Celeron Processor J Series
Intel Celeron Processor N Series
Intel Atom Processor A Series
Intel Pentium Processor Silver Series
Intel Atom processor C3000 series
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
microcode_ctl
intel-microcode (Ubuntu package)
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
How to mitigate CVE-2021-0146
Install updates from vendor's website.
microcode_ctl - update to 2.1-36
intel-microcode (Ubuntu package) - addressed in versions 3.20220510.0ubuntu0.16.04.1+esm1, 3.20220510.0ubuntu0.18.04.1, 3.20220510.0ubuntu0.20.04.1, 3.20220510.0ubuntu0.21.10.1, 3.20220510.0ubuntu0.22.04.1
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
ucode-intel - addressed in versions 20220207-3.38.1, 20220207-3.70.1, 20220207-3.206.1, 20220207-10.1, 20220207-13.93.1
ucode-intel-debuginfo - addressed in versions 20220207-3.38.1, 20220207-13.93.1
ucode-intel-debugsource - addressed in versions 20220207-3.38.1, 20220207-13.93.1
intel-microcode (Ubuntu package) - addressed in versions 3.20220510.0ubuntu0.16.04.1+esm1, 3.20220510.0ubuntu0.18.04.1, 3.20220510.0ubuntu0.20.04.1, 3.20220510.0ubuntu0.21.10.1, 3.20220510.0ubuntu0.22.04.1
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
ucode-intel - addressed in versions 20220207-3.38.1, 20220207-3.70.1, 20220207-3.206.1, 20220207-10.1, 20220207-13.93.1
ucode-intel-debuginfo - addressed in versions 20220207-3.38.1, 20220207-13.93.1
ucode-intel-debugsource - addressed in versions 20220207-3.38.1, 20220207-13.93.1
External References
Related Security Bulletins
- Privilege escalation in Intel processors
- Ubuntu update for intel-microcode
- Ubuntu update for intel-microcode
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Gentoo update for intel-microcode
- openEuler update for microcode_ctl