CVE-2022-21123

medium
Published 2022-11-15 · Modified 2022-11-18
CVSS v3
VIR risk
5.5

Description

Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description hw: cpu: incomplete clean-up of multi-core shared buffers (aka SBDR) Red Hat statement Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third-party…

Description

hw: cpu: incomplete clean-up of multi-core shared buffers (aka SBDR)

Red Hat statement

Red Hat has very limited to no visibility and control over binary blobs provided by third-party vendors. Red Hat relies heavily on the vendors to provide timely updates and information about included changes for this content and in most cases merely acts as a release vehicle between the third-party vendor and Red Hat customers with no possibility of influencing or even documenting the changes. Unless explicitly stated, the level of insight, oversight, and control Red Hat has does not meet the criteria required (in terms of Red Hat ownership of development processes, QA, and documentation) for releasing this content as RHSA. For more information please contact the binary content vendor.

CVSS v3: 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7kernel-rt-0:3.10.0-1160.76.1.rt56.1220.el7RHSA-2022:59392022-08-09T00:00:00Z
Red Hat Enterprise Linux 7kernel-0:3.10.0-1160.76.1.el7RHSA-2022:59372022-08-09T00:00:00Z
Red Hat Enterprise Linux 8kernel-rt-0:4.18.0-372.26.1.rt7.183.el8_6RHSA-2022:64372022-09-13T00:00:00Z
Red Hat Enterprise Linux 8kernel-0:4.18.0-372.26.1.el8_6RHSA-2022:64602022-09-13T00:00:00Z
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionskernel-0:4.18.0-147.76.1.el8_1RHSA-2022:68722022-10-11T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportkernel-0:4.18.0-193.93.1.el8_2RHSA-2022:72792022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-rt-0:4.18.0-193.93.1.rt13.143.el8_2RHSA-2022:72802022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicekernel-0:4.18.0-193.93.1.el8_2RHSA-2022:72792022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionskernel-0:4.18.0-193.93.1.el8_2RHSA-2022:72792022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportkernel-rt-0:4.18.0-305.65.1.rt7.137.el8_4RHSA-2022:69912022-10-18T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportkernel-0:4.18.0-305.65.1.el8_4RHSA-2022:69832022-10-18T00:00:00Z
Red Hat Enterprise Linux 9kernel-0:5.14.0-162.6.1.el9_1RHSA-2022:82672022-11-15T00:00:00Z
Red Hat Enterprise Linux 9kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1RHSA-2022:79332022-11-15T00:00:00Z
Red Hat Enterprise Linux 9kernel-0:5.14.0-162.6.1.el9_1RHSA-2022:82672022-11-15T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportkernel-0:5.14.0-70.36.1.el9_0RHSA-2022:89732022-12-13T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportkernel-rt-0:5.14.0-70.36.1.rt21.108.el9_0RHSA-2022:89742022-12-13T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8kernel-0:4.18.0-372.26.1.el8_6RHSA-2022:64602022-09-13T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 6microcode_ctlAffected
Red Hat Enterprise Linux 7microcode_ctlAffected
Red Hat Enterprise Linux 8microcode_ctlAffected
Red Hat Enterprise Linux 9microcode_ctlAffected

Apply commands

bash fix
Apply RHSA-2022:5939 for Red Hat Enterprise Linux 7
yum update -y kernel-rt
# or:
dnf upgrade -y kernel-rt

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

OSVersionStatusFixed in
almalinux almalinux9fixedkernel-rt-debug-core-5.14.0-162.6.1.rt21.168.el9_1.x86_64.rpm
redhat rhel9fixed
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed3.20220510.1
debian debianbullseyefixed3.20220510.1~deb11u1
debian debianforkyfixed3.20220510.1
debian debiansidfixed3.20220510.1
debian debiantrixiefixed3.20220510.1
rockylinux rocky9fixed
almalinux almalinux8fixedkernel-rt-debug-4.18.0-372.26.1.rt7.183.el8_6.x86_64.rpm

References

💬 Discuss CVE-2022-21123 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.