ALINUX2-SA-2021%3A0047
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2020-0543: Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-0548: Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-0549: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-24489: Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access. CVE-2020-24511: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-24512: Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-8695: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. CVE-2020-8696: Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVE-2020-8698: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | microcode_ctl |
Timeline
- Aug 13, 2021 CVE Published
- Aug 13, 2021 CVE Updated
References
- ALINUX2-SA-2021:0047: microcode_ctl security, bug fix and enhancement update (Important) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24489 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24512 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8695 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8698 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0543 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0548 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0549 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24511 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8696 advisory