Information disclosure in Intel Processor Microcode Package for Linux - CVE-2023-38575
Published: March 13, 2024
Vulnerability identifier: #VU87490
CSH Severity: Low
CVSS v4 BT: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-38575
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to non-transparent sharing of return predictor targets between contexts in some Intel Processors. A local user can gain unauthorized access to sensitive information on the system.
Affected software
Intel Processor Microcode Package for Linux
HPE ProLiant MicroServer Gen11
HPE ProLiant DL20 Gen11
HPE ProLiant ML30 Gen11
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
PowerFlex Appliance
APEX Cloud Platform Foundation Software
Citrix Hypervisor
microcode_ctl
ucode-intel
APEX Cloud Platform for Red Hat OpenShift
HPE ProLiant MicroServer Gen11
HPE ProLiant DL20 Gen11
HPE ProLiant ML30 Gen11
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
PowerFlex Appliance
APEX Cloud Platform Foundation Software
Citrix Hypervisor
microcode_ctl
ucode-intel
APEX Cloud Platform for Red Hat OpenShift
How to mitigate CVE-2023-38575
Install updates from vendor's website.
Intel Processor Microcode Package for Linux - update to 20240312
PowerFlex Appliance - update to IC-46.380.01
Citrix Hypervisor - update to XS82ECU1040
HPE ProLiant MicroServer Gen11 - update to 1.44_01-18-2024
HPE ProLiant DL20 Gen11 - update to 1.44_01-18-2024
HPE ProLiant ML30 Gen11 - update to 1.44_01-18-2024
microcode_ctl - update to 2.1-53
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39
microcode_ctl - update to 20240312-1
ucode-intel - update to 20240312-150200.38.1
PowerFlex Appliance - update to IC-46.380.01
Citrix Hypervisor - update to XS82ECU1040
HPE ProLiant MicroServer Gen11 - update to 1.44_01-18-2024
HPE ProLiant DL20 Gen11 - update to 1.44_01-18-2024
HPE ProLiant ML30 Gen11 - update to 1.44_01-18-2024
microcode_ctl - update to 2.1-53
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39
microcode_ctl - update to 20240312-1
ucode-intel - update to 20240312-150200.38.1
External References
Related Security Bulletins
- Non-transparent sharing of return predictor targets in Intel processors
- Citrix Hypervisor update for Intel firmware
- openEuler update for microcode_ctl
- SUSE update for ucode-intel
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift and Dell APEX Cloud Platform Foundation Software
- Amazon Linux AMI update for microcode_ctl
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Information disclosure in Certain HPE ProLiant DL/ML and MicroServer Servers Using Certain Intel Processors