USN-7149-1: Intel Microcode vulnerabilities
Avraham Shalev and Nagaraju N Kodalapura discovered that some Intel(R) Xeon(R) processors did not properly restrict access to the memory controller when using Intel(R) SGX. This may allow a local privileged attacker to further escalate their privileges. (CVE-2024-21820, CVE-2024-23918) It was discovered that some 4th and 5th Generation Intel(R) Xeon(R) Processors did not properly implement finite state machines (FSMs) in hardware logic. THis may allow a local privileged attacker to cause a denial of service (system crash). (CVE-2024-21853) It was discovered that some Intel(R) Processors did not properly restrict access to the Running Average Power Limit (RAPL) interface. This may allow a local privileged attacker to obtain sensitive information. (CVE-2024-23984) It was discovered that some Intel(R) Processors did not properly implement finite state machines (FSMs) in hardware logic. This may allow a local privileged attacker to cause a denial of service (system crash). (CVE-2024-24968)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7149-1?
The severity of USN-7149-1 is high due to the potential for local privilege escalation.
How do I fix USN-7149-1?
To fix USN-7149-1, update the intel-microcode package to the recommended version corresponding to your Ubuntu release.
What systems are affected by USN-7149-1?
USN-7149-1 affects multiple versions of Ubuntu, specifically 16.04, 18.04, 20.04, 22.04, and 24.04.
Can USN-7149-1 be exploited remotely?
No, USN-7149-1 requires a local privileged attacker to exploit the vulnerability.
What are the CVEs associated with USN-7149-1?
USN-7149-1 is associated with CVE-2024-21820, CVE-2024-23984, and CVE-2024-24968.