Intel on Tuesday issued an out-of-band security update to address a privilege escalation vulnerability in recent server and personal computer chips. The flaw, designated INTEL-SA-00950 and given a CVSS 3.0 score of 8.8 out of 10, affects Intel Sapphire Rapids, Alder Lake, and Raptor Lake chip families. It's being addressed with a microcode update as part of Intel's Patch Tuesday bundle of 31 security advisories that cover 104 CVEs. The top line summary: this vulnerability can be exploited by guest virtual machines to crash the underlying hypervisor host. If that's a problem for you, pay attention to the following. "Intel discovered this issue internally and was already preparing the ecosystem to release a mitigation through our well-documented Intel Platform Update process," the company said in a statement provided to The Register. "At the request of customers, including OEMs and CSPs, this process typically includes a validation, integration, and deployment window after Intel deems the patch meets production quality, and helps ensure that mitigations are available to all customers on all supported Intel platforms when the issue is publicly disclosed. While Intel is not aware of any active attacks using this vulnerability, affected platforms have an available mitigation via a microcode update." According to a post by Jerry Bryant, senior director of incident response and security communications at Intel, the chip biz's own researchers found the vulnerability, dubbed "Redundan...
Intel emits patch to squash chip bug that lets any guest VM crash host servers
The Register
·Thomas Claburn
·Published Nov 14, 2023
·Updated
Affected Software
3 affected components
Intel Sapphire Rapids
Intel Alder Lake
Intel Raptor Lake
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses an out-of-band security patch released by Intel to address a privilege escalation vulnerability affecting certain chips.
2
What security implications are discussed in the article?
The article highlights the risk of a bug that allows guest virtual machines to crash host servers, indicating a significant security vulnerability.
3
What vulnerability is addressed in the Intel patch?
The vulnerability is designated as INTEL-SA-00950 and has a CVSS score of 8.8, indicating its severity.
4
Which Intel products are affected by this security update?
The affected products include Intel's Sapphire Rapids, Alder Lake, and Raptor Lake chips.
5
When was the security patch released by Intel?
Intel issued the security patch on Tuesday, November 14, 2023.