QID 353194
Date Published: 2022-03-09
QID 353194: Amazon Linux Security Advisory for microcode_ctl : ALAS2-2022-1762
A flaw was found in microcode.
Under complex microarchitectural conditions, an unexpected code breakpoint may cause a system hang.
The hang was observed on a skylake server processor, and subsequent analysis indicated additional potentially affected processors.
This flaw allows a possible temporary denial of service (tdos) to occur. (
( CVE-2021-0127) hardware allows activation of test and debug logic at runtime for some intel(r) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access. (
( CVE-2021-0146)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2-2022-1762 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2-2022-1762 -
alas.aws.amazon.com/AL2/ALAS-2022-1762.html
CVEs related to QID 353194
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2022-1762 | Amazon Linux 2 |
|