CVE-2023-23908

Name
CVE-2023-23908
Description
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00836.html
MISC https://www.debian.org/security/2023/dsa-5474
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/
Mailing List https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html
MISC https://security.netapp.com/advisory/ntap-20230824-0003/

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
intel-ucode edge-main 20230808-r0 Marian Buschsieweke <marian.buschsieweke@ovgu.de> fixed
intel-ucode 3.22-main 20230808-r0 None fixed
intel-ucode 3.21-main 20230808-r0 None fixed
intel-ucode 3.20-main 20230808-r0 None fixed
intel-ucode 3.19-main 20230808-r0 None fixed
intel-ucode 3.18-main 20230808-r0 Marian Buschsieweke <marian.buschsieweke@ovgu.de> fixed
intel-ucode 3.17-main 20230808-r0 Marian Buschsieweke <marian.buschsieweke@ovgu.de> fixed