CVE Vulnerabilities

CVE-2022-41804

Unauthorized Error Injection Can Degrade Hardware Redundancy

Published: Aug 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.2 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:H
Ubuntu
MEDIUM

Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Weakness

An unauthorized agent can inject errors into a redundant block to deprive the system of redundancy or put the system in a degraded operating mode.

Affected Software

Name Vendor Start Version End Version
Debian_linux Debian 11.0 (including) 11.0 (including)
Debian_linux Debian 12.0 (including) 12.0 (including)
Fedora Fedoraproject 38 (including) 38 (including)
Intel-microcode Ubuntu bionic *
Intel-microcode Ubuntu devel *
Intel-microcode Ubuntu esm-infra/bionic *
Intel-microcode Ubuntu esm-infra/xenial *
Intel-microcode Ubuntu focal *
Intel-microcode Ubuntu jammy *
Intel-microcode Ubuntu lunar *
Intel-microcode Ubuntu mantic *
Intel-microcode Ubuntu noble *
Intel-microcode Ubuntu oracular *
Intel-microcode Ubuntu trusty *
Intel-microcode Ubuntu trusty/esm *
Intel-microcode Ubuntu xenial *

Extended Description

To ensure the performance and functional reliability of certain components, hardware designers can implement hardware blocks for redundancy in the case that others fail. This redundant block can be prevented from performing as intended if the design allows unauthorized agents to inject errors into it. In this way, a path with injected errors may become unavailable to serve as a redundant channel. This may put the system into a degraded mode of operation which could be exploited by a subsequent attack.

Potential Mitigations

References