Protection Mechanism Failure in Intel Processor Microcode Package for Linux - CVE-2023-39368
Published: March 13, 2024
Vulnerability identifier: #VU87495
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-39368
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient implementation of security measures in the bus lock regulator mechanism. A remote attacker can trick the victim to open a specially crafted file and perform a denial of service (DoS) attack.
Affected software
Intel Processor Microcode Package for Linux
HPE ProLiant DL20 Gen11
HPE ProLiant MicroServer Gen11
HPE ProLiant ML30 Gen11
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
PowerFlex Appliance
APEX Cloud Platform Foundation Software
Citrix Hypervisor
microcode_ctl
ucode-intel
APEX Cloud Platform for Red Hat OpenShift
HPE ProLiant DL20 Gen11
HPE ProLiant MicroServer Gen11
HPE ProLiant ML30 Gen11
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Dell Data Protection Central
PowerProtect DP Series Appliance (IDPA)
PowerFlex Appliance
APEX Cloud Platform Foundation Software
Citrix Hypervisor
microcode_ctl
ucode-intel
APEX Cloud Platform for Red Hat OpenShift
How to mitigate CVE-2023-39368
Install updates from vendor's website.
Intel Processor Microcode Package for Linux - update to 20240312
PowerFlex Appliance - update to IC-46.380.01
Citrix Hypervisor - update to XS82ECU1040
HPE ProLiant DL20 Gen11 - update to 1.44_01-18-2024
HPE ProLiant MicroServer Gen11 - update to 1.44_01-18-2024
HPE ProLiant ML30 Gen11 - update to 1.44_01-18-2024
microcode_ctl - update to 2.1-53
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39
microcode_ctl - update to 20240312-1
ucode-intel - update to 20240312-150200.38.1
PowerFlex Appliance - update to IC-46.380.01
Citrix Hypervisor - update to XS82ECU1040
HPE ProLiant DL20 Gen11 - update to 1.44_01-18-2024
HPE ProLiant MicroServer Gen11 - update to 1.44_01-18-2024
HPE ProLiant ML30 Gen11 - update to 1.44_01-18-2024
microcode_ctl - update to 2.1-53
APEX Cloud Platform Foundation Software - update to 03.00.04.01
APEX Cloud Platform for Red Hat OpenShift - update to 4.13.39
microcode_ctl - update to 20240312-1
ucode-intel - update to 20240312-150200.38.1
External References
Related Security Bulletins
- Remote denial of service in Intel processors bus lock
- Citrix Hypervisor update for Intel firmware
- openEuler update for microcode_ctl
- SUSE update for ucode-intel
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift and Dell APEX Cloud Platform Foundation Software
- Amazon Linux AMI update for microcode_ctl
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Protection mechanism failure in Certain HPE ProLiant DL/ML and MicroServer Using Certain Intel Processors