Advisories ยป MGASA-2024-0207

Updated microcode packages fix security vulnerabilities

Publication date: 03 Jun 2024
Modification date: 03 Jun 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-45733 , CVE-2023-46103 , CVE-2023-45745

Description

The updated package fixes security vulnerabilities:
Hardware logic contains race conditions in some Intel(R) Processors may
allow an authenticated user to potentially enable partial information
disclosure via local access. (CVE-2023-45733)
Sequence of processor instructions leads to unexpected behavior in
Intel(R) Core(TM) Ultra Processors may allow an authenticated user to
potentially enable denial of service via local access. (CVE-2023-46103)
Improper input validation in some Intel(R) TDX module software before
version 1.5.05.46.698 may allow a privileged user to potentially enable
escalation of privilege via local access. (CVE-2023-45745)
                

References

SRPMS

9/nonfree