Moderate: microcode_ctl security update
The microcode_ctl packages provide microcode updates for Intel and AMD processors. Security Fix(es): * kernel: local privilege escalation on Intel microcode on Intel(R) Xeon(R) (CVE-2023-22655) * kernel: Local information disclosure on Intel(R) Atom(R) processors (CVE-2023-28746) * kernel: Local information disclosure in some Intel(R) processors (CVE-2023-38575) * kernel: Possible Denial of Service on Intel(R) Processors (CVE-2023-39368) * kernel: Local information disclosure on Intel(R) Xeon(R) D processors with Intel(R) SGX due to incorrect calculation in microcode (CVE-2023-43490) * intel-microcode: Race conditions in some Intel(R) Processors (CVE-2023-45733) * intel-microcode: Unexpected behavior in Intel(R) Core(TM) Ultra Processors (CVE-2023-46103) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The microcode_ctl packages provide microcode updates for Intel and AMD processors. Security Fix(es): * kernel: local privilege escalation on Intel microcode on Intel(R) Xeon(R) (CVE-2023-22655) * kernel: Local information disclosure on Intel(R) Atom(R) processors (CVE-2023-28746) * kernel: Local information disclosure in some Intel(R) processors (CVE-2023-38575) * kernel: Possible Denial of Service on Intel(R) Processors (CVE-2023-39368) * kernel: Local information disclosure on Intel(R) Xeon(R) D processors with Intel(R) SGX due to incorrect calculation in microcode (CVE-2023-43490) * intel-microcode: Race conditions in some Intel(R) Processors (CVE-2023-45733) * intel-microcode: Unexpected behavior in Intel(R) Core(TM) Ultra Processors (CVE-2023-46103) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2024:9401
- https://access.redhat.com/security/cve/CVE-2023-22655
- https://access.redhat.com/security/cve/CVE-2023-28746
- https://access.redhat.com/security/cve/CVE-2023-38575
- https://access.redhat.com/security/cve/CVE-2023-39368
- https://access.redhat.com/security/cve/CVE-2023-43490
- https://access.redhat.com/security/cve/CVE-2023-45733
- https://access.redhat.com/security/cve/CVE-2023-46103
- https://bugzilla.redhat.com/2270698
- https://bugzilla.redhat.com/2270700
- https://bugzilla.redhat.com/2270701
- https://bugzilla.redhat.com/2270703
- https://bugzilla.redhat.com/2270704
- https://bugzilla.redhat.com/2292296
- https://bugzilla.redhat.com/2292300
- https://errata.almalinux.org/9/ALSA-2024-9401.html