QID 198411

Date Published: 2021-06-28

QID 198411: Ubuntu Security Notification for Intel Microcode vulnerabilities (USN-4985-1)

Some intel processors may not properly invalidate cache entries used by intel virtualization technology for directed i/o (vt-d).some intel processors may not properly apply eibrs mitigations (originally developed for cve-2017-5715) and hence may allow unauthorized memory reads via sidechannel attacks.
Some intel processors did not properly flush cache-lines for trivial-data values.
Certain intel atom processors could expose memory contents stored in microarchitectural buffers.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

this may allow a local user to perform a privilege escalation attack. (
Cve-2020-24489).
A local attacker could use this to expose sensitive information, including kernel memory. (
Cve-2020-24511).
This may allow an unauthorized user to infer the presence of these trivial-data-cache-lines via timing sidechannel attacks.
A local attacker could use this to expose sensitive information. (
Cve-2020-24512).
A local attacker could use this to expose sensitive information. (
Cve-2020-24513).

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4985-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198411

    Software Advisories
    Advisory ID Software Component Link
    USN-4985-1 Ubuntu Linux URL Logo usn.ubuntu.com/4985-1