Improper isolation or compartmentalization in Intel Processor Microcode Package for Linux - CVE-2023-42667

 

Improper isolation or compartmentalization in Intel Processor Microcode Package for Linux - CVE-2023-42667

Published: August 20, 2024


Vulnerability identifier: #VU96257
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-42667
CWE-ID: CWE-653
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper isolation in the Intel Core Ultra Processor stream cache mechanism. A local user can execute arbitrary code with elevated privileges.


Affected software

Intel Processor Microcode Package for Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
CloudBoost Virtual Appliance

How to mitigate CVE-2023-42667

Install updates from vendor's website.

Intel Processor Microcode Package for Linux - update to 20240813
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
CloudBoost Virtual Appliance - update to 19.12.0.1
microcode_ctl - update to 20240813-1
ucode-intel - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel-debugsource - update to 20240813-140.1

External References

Related Security Bulletins