Incorrect calculation in 3rd Generation Intel Xeon Scalable Processors - CVE-2022-33972

 

Incorrect calculation in 3rd Generation Intel Xeon Scalable Processors - CVE-2022-33972

Published: February 21, 2023


Vulnerability identifier: #VU72477
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33972
CWE-ID: CWE-682
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to incorrect calculation in microcode keying mechanism. A local user can gain access to sensitive information.


Affected software

3rd Generation Intel Xeon Scalable Processors
PowerEdge T150
PowerEdge R250
PowerEdge T350
PowerEdge R350
PowerEdge R650XS
PowerEdge R750XA
PowerEdge R650
PowerEdge R750
PowerEdge C6520
PowerEdge MX750c
PowerEdge T550
PowerEdge R450
PowerEdge R750XS
PowerEdge R550
PowerEdge XR12
PowerEdge XR11
HPE Edgeline e920t Server Blade
HPE Edgeline e920d Server Blade
HPE Edgeline e920 Server Blade
HPE ProLiant XL220n Gen10 Plus Server
HPE ProLiant XL290n Gen10 Plus Server
HPE Apollo 2000 Gen10 Plus System
HPE Apollo 4200 Gen10 Plus System
HPE ProLiant DL110 Gen10 Plus Telco server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL380 Gen10 Plus server
HPE StoreEasy 1660 Storage
HPE StoreEasy 1860 Storage
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX380 Gen10 Plus server
PowerEdge T140
PowerEdge T340
PowerEdge R240
PowerEdge R340
PowerEdge R640
PowerEdge T640
PowerEdge R940XA
PowerEdge R840
PowerEdge R740XD2
PowerEdge C4140
PowerEdge T440
PowerEdge R440
PowerEdge R540
PowerEdge R940
PowerEdge XR2
PowerEdge R740XD
PowerEdge R740
PowerEdge FC640
PowerEdge DSS8440
PowerEdge XE2420
PowerEdge XE7420
PowerEdge XE7440
PowerEdge MX840C
PowerEdge C6420
PowerEdge M640
PowerEdge M640P
PowerEdge MX740C
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
F5OS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
PowerFlex Appliance
PowerFlex rack
EMC Cloud Tiering Appliance
Isolation Segment
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel-debuginfo
ucode-intel
ucode-intel-debugsource
RecoverPoint for VMs
Dell EMC NetWorker vProxy

How to mitigate CVE-2022-33972

Install updates from vendor's website.

F5OS - update to 1.5.0
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20230214.0ubuntu0.18.04.1, 3.20230214.0ubuntu0.20.04.1, 3.20230214.0ubuntu0.22.04.1, 3.20230214.0ubuntu0.22.10.1
PowerFlex Appliance - update to IC 38.363.02
PowerEdge T150 - update to 1.5.0
PowerEdge R250 - update to 1.5.0
PowerEdge T350 - update to 1.5.0
PowerEdge R350 - update to 1.5.0
PowerEdge R650XS - update to 1.9.2
PowerEdge R750XA - update to 1.9.2
PowerEdge R650 - update to 1.9.2
PowerEdge R750 - update to 1.9.2
PowerEdge C6520 - update to 1.9.2
PowerEdge MX750c - update to 1.9.2
PowerEdge T550 - update to 1.9.2
PowerEdge R450 - update to 1.9.2
PowerEdge R750XS - update to 1.9.2
PowerEdge R550 - update to 1.9.2
PowerEdge XR12 - update to 1.9.2
PowerEdge XR11 - update to 1.9.2
HPE Edgeline e920t Server Blade - update to 1.66_02-02-2023
HPE Edgeline e920d Server Blade - update to 1.66_02-02-2023
HPE Edgeline e920 Server Blade - update to 1.66_02-02-2023
HPE ProLiant XL220n Gen10 Plus Server - update to 1.72_02-02-2023
HPE ProLiant XL290n Gen10 Plus Server - update to 1.72_02-02-2023
HPE Apollo 2000 Gen10 Plus System - update to 1.72_02-02-2023
HPE Apollo 4200 Gen10 Plus System - update to 1.72_02-02-2023
HPE ProLiant DL110 Gen10 Plus Telco server - update to 1.72_02-02-2023
HPE ProLiant DL360 Gen10 Plus server - update to 1.72_02-02-2023
HPE ProLiant DL380 Gen10 Plus server - update to 1.72_02-02-2023
HPE StoreEasy 1660 Storage - update to 1.72_02-02-2023
HPE StoreEasy 1860 Storage - update to 1.72_02-02-2023
HPE ProLiant DX360 Gen10 Plus server - update to 1.72_02-02-2023
HPE ProLiant DX380 Gen10 Plus server - update to 1.72_02-02-2023
microcode_ctl - update to 2.1-53
microcode_ctl - addressed in versions 2.1-53.1.fc37, 2.1-55.fc38
PowerEdge T140 - update to 2.12.2
PowerEdge T340 - update to 2.12.2
PowerEdge R240 - update to 2.12.2
PowerEdge R340 - update to 2.12.2
PowerEdge R640 - update to 2.17.1
PowerEdge T640 - update to 2.17.1
PowerEdge R940XA - update to 2.17.1
PowerEdge R840 - update to 2.17.1
PowerEdge R740XD2 - update to 2.17.1
PowerEdge C4140 - update to 2.17.1
PowerEdge T440 - update to 2.17.1
PowerEdge R440 - update to 2.17.1
PowerEdge R540 - update to 2.17.1
PowerEdge R940 - update to 2.17.1
PowerEdge XR2 - update to 2.17.1
PowerEdge R740XD - update to 2.17.1
PowerEdge R740 - update to 2.17.1
PowerEdge FC640 - update to 2.17.1
PowerEdge DSS8440 - update to 2.17.1
PowerEdge XE2420 - update to 2.17.1
PowerEdge XE7420 - update to 2.17.1
PowerEdge XE7440 - update to 2.17.1
PowerEdge MX840C - update to 2.17.1
PowerEdge C6420 - update to 2.17.1
PowerEdge M640 - update to 2.17.1
PowerEdge M640P - update to 2.17.1
PowerEdge MX740C - update to 2.17.1
PowerFlex rack - update to 3.6.3.2
RecoverPoint for VMs - update to 6.0.SP1.P1
EMC Cloud Tiering Appliance - update to 13.1.0.2.33
Dell EMC NetWorker vProxy - addressed in versions 19.8.0.3, 19.9.0.2
ucode-intel-debuginfo - addressed in versions 20230512-3.52.1, 20230512-13.107.1
ucode-intel - addressed in versions 20230512-3.52.1, 20230512-13.107.1, 20230512-150100.3.220.1, 20230512-150200.24.1
ucode-intel-debugsource - addressed in versions 20230512-3.52.1, 20230512-13.107.1

External References

Related Security Bulletins