[ALAS2-2024-2491] Amazon Linux 2 2017.12 - ALAS2-2024-2491: medium priority package update for microcode_ctl

Severity Medium
Affected Packages 4
CVEs 2

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2023-39368:
Protection mechanism failure of bus lock regulator for some Intel? Processors may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2023-38575:
Non-transparent sharing of return predictor targets between contexts in some Intel? Processors may allow an authorized user to potentially enable information disclosure via local access.

ID
ALAS2-2024-2491
Severity
medium
URL
https://alas.aws.amazon.com/AL2/ALAS-2024-2491.html
Published
2024-03-11T21:19:00
(6 months ago)
Modified
2024-03-11T21:19:00
(6 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/microcode_ctl?arch=x86_64&distro=amazonlinux-2 amazonlinux microcode_ctl < 2.1-47.amzn2.4.17 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/microcode_ctl?arch=i686&distro=amazonlinux-2 amazonlinux microcode_ctl < 2.1-47.amzn2.4.17 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/microcode_ctl-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux microcode_ctl-debuginfo < 2.1-47.amzn2.4.17 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/microcode_ctl-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux microcode_ctl-debuginfo < 2.1-47.amzn2.4.17 amazonlinux-2 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...