FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Intel CPUs -- multiple vulnerabilities

Affected packages
cpu-microcode-intel < 20240514

Details

VuXML ID 5afd64ae-122a-11ef-8eed-1c697a616631
Discovery 2024-05-14
Entry 2024-05-14

Intel reports:

Potential security vulnerabilities in some Intel Trust Domain Extensions (TDX) module software may allow escalation of privilege. Improper input validation in some Intel TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. Intel is releasing firmware updates to mitigate these potential vulnerabilities.

A potential security vulnerability in some Intel Processors may allow information disclosure. Hardware logic contains race conditions in some Intel Processors that may allow an authenticated user to potentially enable partial information disclosure via local access. Intel is releasing microcode updates to mitigate this potential vulnerability.

A potential security vulnerability in Intel Core Ultra Processors may allow denial of service. Sequence of processor instructions leads to unexpected behavior in Intel Core Ultra Processors may allow an authenticated user to potentially enable denial of service via local access. Intel is releasing microcode updates to mitigate this potential vulnerability.

References

CVE Name CVE-2023-45733
CVE Name CVE-2023-45745
CVE Name CVE-2023-46103
URL https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20240514