CVE-2020-0543: Medium severity Intel Celeron 1000m vulnerability
A new domain bypass transient execution attack known as Special Register Buffer Data Sampling (SRBDS) has been found. This flaw allows data values from special internal registers to be leaked by an attacker able to execute code on any core of the CPU. An unprivileged, local attacker can use this flaw to infer values returned by affected instructions known to be commonly used during cryptographic operations that rely on uniqueness, secrecy, or both.
Other sources
Certain microprocessor operations (including RDRAND and RDSEED) are implemented using micro-architecture specific Special Register Reads (SRR). On certain client and E3 processors, the data returned by these SRR operations may be inferred, even on another core. Cleanup errors from specific special register read operations may allow an authenticated user to potentially enable information disclosure via local access.
— Red Hat
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240813.1~deb11u1Fixed in 3.20250812.1~deb11u1Fixed in 3.20251111.1~deb12u1Fixed in 3.20250812.1~deb12u1Fixed in 3.20251111.1~deb13u1Fixed in 3.20250812.1~deb13u1Fixed in 3.20260227.1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2020-0543.
What is the severity of CVE-2020-0543?
The severity of CVE-2020-0543 is medium with a score of 6.5.
How does CVE-2020-0543 affect Intel processors?
CVE-2020-0543 allows data values from special internal registers to be leaked by an attacker able to execute code on any core of the CPU.
Which software versions are affected by CVE-=2020-0543?
The affected software versions include intel-microcode 3.20200609.0ubuntu0.20.04.0, intel-microcode 3.20200609.0ubuntu0.18.04.0, intel-microcode 3.20200609.0ubuntu0.19.10.0, intel-microcode 3.20200609.0ubuntu0.14.04.0, intel-microcode 3.20200609.0ubuntu0.16.04.0, intel-microcode 4.14, xen 4.11.3+24-, and intel-microcode 3.20220510.1~deb10u1, 3.20230808.1~deb10u1, 3.20230214.1~deb11u1, 3.20230808.1~deb11u1, 3.20230512.1, 3.20230808.1~deb12u1, 3.20230808.1.
Where can I find more information about CVE-2020-0543?
You can find more information about CVE-2020-0543 at the following references: [link1], [link2], [link3].