FlawAtlas
Search the atlas
USN-6286-1 Not scored

intel-microcode vulnerabilities

Daniel Moghimi discovered that some Intel(R) Processors did not properly clear microarchitectural state after speculative execution of various instructions. A local unprivileged user could use this to obtain to sensitive information. (CVE-2022-40982) It was discovered that some Intel(R) Xeon(R) Processors did not properly restrict error injection for Intel(R) SGX or Intel(R) TDX. A local privileged user could use this to further escalate their privileges. (CVE-2022-41804) It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable processors did not properly restrict access in some situations. A local privileged attacker could use this to obtain sensitive information. (CVE-2023-23908)

Exploit probability Not scored
Published August 14, 2023
Required by Not available
Last source change June 25, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:20.04:LTS intel-microcode

14 explicit affected versions

Ubuntu:22.04:LTS intel-microcode

4 explicit affected versions

Ubuntu:Pro:16.04:LTS intel-microcode

23 explicit affected versions

Ubuntu:Pro:18.04:LTS intel-microcode

23 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-6286-1

Daniel Moghimi discovered that some Intel(R) Processors did not properly clear microarchitectural state after speculative execution of various instructions. A local unprivileged user could use this to obtain to sensitive information. (CVE-2022-40982) It was discovered that some Intel(R) Xeon(R) Processors did not properly restrict error injection for Intel(R) SGX or Intel(R) TDX. A local privileged user could use this to further escalate their privileges. (CVE-2022-41804) It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable processors did not properly restrict access in some situations. A local privileged attacker could use this to obtain sensitive information. (CVE-2023-23908)

View original source

05 / REFERENCES

Further evidence