ALINUX2-SA-2021%3A0038
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2020-24489: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access. CVE-2020-24511: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-24512: Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-24513: Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | microcode_ctl |
Timeline
- Jun 9, 2021 CVE Published
- Jun 9, 2021 CVE Updated
References
- ALINUX2-SA-2021:0038: microcode_ctl security, bug fix and enhancement update (Important) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24489 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24511 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24512 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24513 advisory