CVE Vulnerabilities

CVE-2022-41804

Unauthorized Error Injection Can Degrade Hardware Redundancy

Published: Aug 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.2 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Weakness

An unauthorized agent can inject errors into a redundant block to deprive the system of redundancy or put the system in a degraded operating mode.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian11.0 (including)11.0 (including)
Debian_linuxDebian12.0 (including)12.0 (including)
FedoraFedoraproject38 (including)38 (including)
Red Hat Enterprise Linux 7RedHatmicrocode_ctl-2:2.1-73.19.el7_9*
Red Hat Enterprise Linux 8RedHatmicrocode_ctl-4:20220809-2.20230808.2.el8_8*
Red Hat Enterprise Linux 9RedHatmicrocode_ctl-4:20220809-2.20230808.2.el9_2*
Intel-microcodeUbuntubionic*
Intel-microcodeUbuntudevel*
Intel-microcodeUbuntuesm-infra-legacy/trusty*
Intel-microcodeUbuntuesm-infra/bionic*
Intel-microcodeUbuntuesm-infra/focal*
Intel-microcodeUbuntuesm-infra/xenial*
Intel-microcodeUbuntufocal*
Intel-microcodeUbuntujammy*
Intel-microcodeUbuntulunar*
Intel-microcodeUbuntumantic*
Intel-microcodeUbuntunoble*
Intel-microcodeUbuntuoracular*
Intel-microcodeUbuntutrusty*
Intel-microcodeUbuntutrusty/esm*
Intel-microcodeUbuntuxenial*

Extended Description

To ensure the performance and functional reliability of certain components, hardware designers can implement hardware blocks for redundancy in the case that others fail. This redundant block can be prevented from performing as intended if the design allows unauthorized agents to inject errors into it. In this way, a path with injected errors may become unavailable to serve as a redundant channel. This may put the system into a degraded mode of operation which could be exploited by a subsequent attack.

Potential Mitigations

References