Protection Mechanism Failure in Intel Processor Microcode Package for Linux - CVE-2023-39368

 

Protection Mechanism Failure in Intel Processor Microcode Package for Linux - CVE-2023-39368

Published: March 13, 2024


Vulnerability identifier: #VU87495
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-39368
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient implementation of security measures in the bus lock regulator mechanism. A remote attacker can trick the victim to open a specially crafted file and perform a denial of service (DoS) attack.


Affected software

Intel Processor Microcode Package for Linux
HPE ProLiant DL20 Gen11
HPE ProLiant MicroServer Gen11
HPE ProLiant ML30 Gen11
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
PowerFlex Appliance
APEX Cloud Platform Foundation Software
Citrix Hypervisor
microcode_ctl
ucode-intel
APEX Cloud Platform for Red Hat OpenShift

How to mitigate CVE-2023-39368

Install updates from vendor's website.

Intel Processor Microcode Package for Linux - update to 20240312
PowerFlex Appliance - update to IC-46.380.01
Citrix Hypervisor - update to XS82ECU1040
HPE ProLiant DL20 Gen11 - update to 1.44_01-18-2024
HPE ProLiant MicroServer Gen11 - update to 1.44_01-18-2024
HPE ProLiant ML30 Gen11 - update to 1.44_01-18-2024
microcode_ctl - update to 2.1-53
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39
microcode_ctl - update to 20240312-1
ucode-intel - update to 20240312-150200.38.1

External References

Related Security Bulletins