USN-7077-1: AMD Microcode vulnerability
Enrique Nissim and Krzysztof Okupski discovered that some AMD processors did not properly restrict access to the System Management Mode (SMM) configuration when the SMM Lock was enabled. A privileged local attacker could possibly use this issue to further escalate their privileges and execute arbitrary code within the processor's firmware layer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7077-1?
The severity of USN-7077-1 is considered medium due to the potential for privilege escalation by a local attacker.
How do I fix USN-7077-1?
To fix USN-7077-1, you should upgrade the amd64-microcode package to the recommended remedial versions based on your Ubuntu version.
Which Ubuntu versions are affected by USN-7077-1?
The affected Ubuntu versions for USN-7077-1 include 16.04, 18.04, 20.04, 22.04, and 24.04.
What specific packages do I need to update for USN-7077-1?
You need to update the amd64-microcode package to the appropriate version listed in the USN-7077-1 advisory.
Is there a known exploit for USN-7077-1?
There are no public exploits known for USN-7077-1 as of now, but it is still recommended to patch the vulnerability promptly.