[USN-4628-1] Intel Microcode vulnerabilities

Severity Medium
Affected Packages 5
CVEs 3

Several security issues were fixed in Intel Microcode.

Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)

Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive information
before storage or transfer in some situations. A local attacker could
possibly use this to expose sensitive information. (CVE-2020-8696)

Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly isolate shared resources in some
situations. A local attacker could possibly use this to expose sensitive
information. (CVE-2020-8698)

Package Affected Version
pkg:deb/ubuntu/intel-microcode?distro=xenial < 3.20201110.0ubuntu0.16.04.1
pkg:deb/ubuntu/intel-microcode?distro=trusty < 3.20201110.0ubuntu0.14.04.1
pkg:deb/ubuntu/intel-microcode?distro=groovy < 3.20201110.0ubuntu0.20.10.1
pkg:deb/ubuntu/intel-microcode?distro=focal < 3.20201110.0ubuntu0.20.04.1
pkg:deb/ubuntu/intel-microcode?distro=bionic < 3.20201110.0ubuntu0.18.04.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/intel-microcode?distro=xenial ubuntu intel-microcode < 3.20201110.0ubuntu0.16.04.1 xenial
Affected pkg:deb/ubuntu/intel-microcode?distro=trusty ubuntu intel-microcode < 3.20201110.0ubuntu0.14.04.1 trusty
Affected pkg:deb/ubuntu/intel-microcode?distro=groovy ubuntu intel-microcode < 3.20201110.0ubuntu0.20.10.1 groovy
Affected pkg:deb/ubuntu/intel-microcode?distro=focal ubuntu intel-microcode < 3.20201110.0ubuntu0.20.04.1 focal
Affected pkg:deb/ubuntu/intel-microcode?distro=bionic ubuntu intel-microcode < 3.20201110.0ubuntu0.18.04.1 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...