SB2022022533 - SUSE update for ucode-intel
Published: February 25, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2021-0127)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient control flow management. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
2) Information disclosure (CVE-ID: CVE-2021-0145)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to improper initialization of shared resources. A local user can gain unauthorized access to sensitive information on the system.
3) Security features bypass (CVE-ID: CVE-2021-0146)
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to hardware allows activation of test or debug logic at runtime. An attacker with physical access to device can execute arbitrary code with elevated privileges.
4) Out-of-bounds read (CVE-ID: CVE-2021-33120)
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to a boundary condition in memory subsystem. A local user can trigger out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.