First published: Mon Aug 14 2023(Updated: )
Daniel Moghimi discovered that some Intel(R) Processors did not properly clear microarchitectural state after speculative execution of various instructions. A local unprivileged user could use this to obtain to sensitive information. (CVE-2022-40982) It was discovered that some Intel(R) Xeon(R) Processors did not properly restrict error injection for Intel(R) SGX or Intel(R) TDX. A local privileged user could use this to further escalate their privileges. (CVE-2022-41804) It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable processors did not properly restrict access in some situations. A local privileged attacker could use this to obtain sensitive information. (CVE-2023-23908)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/intel-microcode | <3.20230808.0ubuntu1 | 3.20230808.0ubuntu1 |
=23.04 | ||
All of | ||
ubuntu/intel-microcode | <3.20230808.0ubuntu0.22.04.1 | 3.20230808.0ubuntu0.22.04.1 |
=22.04 | ||
All of | ||
ubuntu/intel-microcode | <3.20230808.0ubuntu0.20.04.1 | 3.20230808.0ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/intel-microcode | <3.20230808.0ubuntu0.18.04.1+esm1 | 3.20230808.0ubuntu0.18.04.1+esm1 |
=18.04 | ||
All of | ||
ubuntu/intel-microcode | <3.20230808.0ubuntu0.16.04.1+esm1 | 3.20230808.0ubuntu0.16.04.1+esm1 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for USN-6286-1 is CVE-2022-40982.
The vulnerability in Intel Microcode allows a local unprivileged user to obtain sensitive information.
The versions of Ubuntu affected are 23.04, 22.04, 20.04, 18.04, and 16.04.
The remedy for the vulnerability is to update the intel-microcode package to version 3.20230808.0ubuntu1 for Ubuntu 23.04, version 3.20230808.0ubuntu0.22.04.1 for Ubuntu 22.04, version 3.20230808.0ubuntu0.20.04.1 for Ubuntu 20.04, version 3.20230808.0ubuntu0.18.04.1+esm1 for Ubuntu 18.04, and version 3.20230808.0ubuntu0.16.04.1+esm1 for Ubuntu 16.04.
You can find more information about the Intel Microcode vulnerabilities on the Ubuntu security advisory pages for CVE-2022-40982, CVE-2023-23908, and CVE-2022-41804.