Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
A flaw was found in the implementation of Intel Advanced Vector Extensions (AVX) where a local authenticated attacker with the ability to execute AVX instructions is able to gather AVX register state from previous AVX executions.
This could allow information disclosure of AVX register state.
A vulnerability was found in Intel's implementation of RAPL (Running Average Power Limit). An attacker with a local account could query the power management functionality to intelligently infer SGX enclave computation values by measuring power usage in the RAPL subsystem.
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
A flaw was found during cache eviction on some Intel processors which may allow a local attacker to infer cache contents and disclose information through this side-channel.
Reference: ---------- -> https://access.redhat.com/solutions/l1d-cache-eviction-and-vector-register-sampling
Additional information: ----------------------- -> https://en.wikipedia.org/wiki/Vectorprocessor -> https://software.intel.com/en-us/articles/introduction-to-intel-advanced-vector-extensions
A flaw was found in Intel processors where a local attacker is able to gain information about registers used for vector calculations by observing register states from other processes running on the system. This results in a race condition where store buffers, which were not cleared, could be read by another process or a CPU sibling. The highest threat from this vulnerability is data confidentiality where an attacker could read arbitrary data as it passes through the processor.
Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.
Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial escalation of privilege, denial of service and/or information disclosure via local access.
Insufficient memory protection in Intel(R) TXT for certain Intel(R) Core Processors and Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Logic condition in specific microprocessors may allow an authenticated user to potentially enable partial physical address information disclosure via local access.
An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions past bounds check.
It relies on the presence of a precisely-defined instruction sequence in the privileged code and the fact that memory writes occur to an address which depends on the untrusted value. Such writes cause an update into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire).
As a result, an unprivileged attacker could use this flaw to influence speculative execution and/or read privileged memory by conducting targeted cache side-channel attacks.