kernel: Intel firmware update for incorrect calculation in microcode keying mechanism
Published Feb 16, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.22%
Description
Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.
Affected products
- Vendor n/a Product 3rd Generation Intel(R) Xeon(R) Scalable Processors Defaultunaffected
Affected
- See references
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | 3rd Generation Intel(R) Xeon(R) Scalable Processors | unaffected | Affected
|
Configuration 1
- n/a
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- n/a
Running on/with
- n/a
Configuration 8
- n/a
Running on/with
- n/a
Configuration 9
- n/a
Running on/with
- n/a
Configuration 10
- n/a
Running on/with
- n/a
Configuration 11
- n/a
Running on/with
- n/a
Configuration 12
- n/a
Running on/with
- n/a
Configuration 13
- n/a
Running on/with
- n/a
Configuration 14
- n/a
Running on/with
- n/a
Configuration 15
- n/a
Running on/with
- n/a
Configuration 16
- n/a
Running on/with
- n/a
Configuration 17
- n/a
Running on/with
- n/a
Configuration 18
- n/a
Running on/with
- n/a
Configuration 19
- n/a
Running on/with
- n/a
Configuration 20
- n/a
Running on/with
- n/a
Configuration 21
- n/a
Running on/with
- n/a
Configuration 22
- n/a
Running on/with
- n/a
Configuration 23
- n/a
Running on/with
- n/a
Configuration 24
- n/a
Running on/with
- n/a
Configuration 25
- n/a
Running on/with
- n/a
Configuration 26
- n/a
Running on/with
- n/a
Configuration 27
- n/a
Running on/with
- n/a
Configuration 28
- n/a
Running on/with
- n/a
Configuration 29
- n/a
Running on/with
- n/a
Configuration 30
- n/a
Running on/with
- n/a
Configuration 31
- n/a
Running on/with
- n/a
Configuration 32
- n/a
Running on/with
- n/a
Configuration 33
- n/a
Running on/with
- n/a
Configuration 34
- n/a
Running on/with
- n/a
Configuration 35
- n/a
Running on/with
- n/a
Configuration 36
- n/a
Running on/with
- n/a
Configuration 37
- n/a
Running on/with
- n/a
Configuration 38
- n/a
Running on/with
- n/a
Configuration 39
- n/a
Running on/with
- n/a
Configuration 40
- n/a
Running on/with
- n/a
Configuration 41
- n/a
Running on/with
- n/a
Configuration 42
- n/a
Running on/with
- n/a
Configuration 43
- n/a
Running on/with
- n/a
Configuration 44
- n/a
Running on/with
- n/a
Configuration 45
- n/a
Running on/with
- n/a
Configuration 46
- n/a
Running on/with
- n/a
Configuration 47
- n/a
Running on/with
- n/a
Configuration 48
- n/a
Running on/with
- n/a
Configuration 49
- n/a
Running on/with
- n/a
Configuration 50
- n/a
Running on/with
- n/a
Configuration 51
- n/a
Running on/with
- n/a
Configuration 52
- n/a
Running on/with
- n/a
Configuration 53
- n/a
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 6
microcode_ctl
Out of support scope
Red Hat Enterprise Linux 7
microcode_ctl
Will not fix
Red Hat Enterprise Linux 8
microcode_ctl
Affected
Red Hat Enterprise Linux 9
microcode_ctl
Affected
Red Hat Virtualization 4
redhat-virtualization-host
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | microcode_ctl | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | microcode_ctl | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | microcode_ctl | Affected | n/a |
| Red Hat Enterprise Linux 9 | microcode_ctl | Affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has very limited visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content. In most cases, it merely acts as a release vehicle between the third-party vendor and Red Hat customers, with no possibility of influencing or documenting the changes. Unless explicitly stated, the level of insight, oversight, and control Red Hat has does not meet the criteria required for releasing this content as a RHSA, in terms of Red Hat-owned development processes and QA documentation. For more information, please contact the binary content vendor.
References (9)
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00730.html Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2022-33972 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2171243 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37008 Advisory
- https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20230214
- https://nvd.nist.gov/vuln/detail/CVE-2022-33972
- https://security.netapp.com/advisory/ntap-20230302-0012/
- https://www.cve.org/CVERecord?id=CVE-2022-33972
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00730.html
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data