CVE-2021-0146
Published: 17 November 2021
Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Notes
Author | Note |
---|---|
alexmurray |
Updates available in upstream release https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220207 |
Priority
Status
Package | Release | Status |
---|---|---|
intel-microcode
Launchpad, Ubuntu, Debian |
bionic |
Released
(3.20220510.0ubuntu0.18.04.1)
|
focal |
Released
(3.20220510.0ubuntu0.20.04.1)
|
|
impish |
Released
(3.20220510.0ubuntu0.21.10.1)
|
|
jammy |
Released
(3.20220510.0ubuntu0.22.04.1)
|
|
kinetic |
Released
(3.20220207.1ubuntu1)
|
|
trusty |
Ignored
(early microcode loading not allowed)
|
|
upstream |
Released
(3.20220207.1)
|
|
xenial |
Released
(3.20220510.0ubuntu0.16.04.1+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.8 |
Attack vector | Physical |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html
- https://security.netapp.com/advisory/ntap-20211210-0006/
- https://ubuntu.com/security/notices/USN-5486-1
- https://ubuntu.com/security/notices/USN-5535-1
- https://www.cve.org/CVERecord?id=CVE-2021-0146
- NVD
- Launchpad
- Debian