USN-7077-1

Source
https://ubuntu.com/security/notices/USN-7077-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7077-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7077-1
Related
Published
2024-10-21T00:06:41.888185Z
Modified
2024-10-21T00:06:41.888185Z
Summary
amd64-microcode vulnerability
Details

Enrique Nissim and Krzysztof Okupski discovered that some AMD processors did not properly restrict access to the System Management Mode (SMM) configuration when the SMM Lock was enabled. A privileged local attacker could possibly use this issue to further escalate their privileges and execute arbitrary code within the processor's firmware layer.

References

Affected packages

Ubuntu:Pro:16.04:LTS / amd64-microcode

Package

Name
amd64-microcode
Purl
pkg:deb/ubuntu/amd64-microcode?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20191021.1+really3.20180524.1~ubuntu0.16.04.2+esm3

Affected versions

2.*

2.20141028.1
2.20160316.1

3.*

3.20180524.1~ubuntu0.16.04.1
3.20180524.1~ubuntu0.16.04.2
3.20191021.1ubuntu0.16.04.1
3.20191021.1+really3.20180524.1~ubuntu0.16.04.2
3.20191021.1+really3.20180524.1~ubuntu0.16.04.2+esm1
3.20191021.1+really3.20180524.1~ubuntu0.16.04.2+esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.20191021.1+really3.20180524.1~ubuntu0.16.04.2+esm3",
            "binary_name": "amd64-microcode"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / amd64-microcode

Package

Name
amd64-microcode
Purl
pkg:deb/ubuntu/amd64-microcode?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20191021.1+really3.20181128.1~ubuntu0.18.04.1+esm3

Affected versions

3.*

3.20160316.3
3.20171205.1
3.20180524.1~ubuntu0.18.04.1
3.20180524.1~ubuntu0.18.04.2
3.20191021.1ubuntu0.18.04.2
3.20191021.1+really3.20181128.1~ubuntu0.18.04.1
3.20191021.1+really3.20181128.1~ubuntu0.18.04.1+esm1
3.20191021.1+really3.20181128.1~ubuntu0.18.04.1+esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.20191021.1+really3.20181128.1~ubuntu0.18.04.1+esm3",
            "binary_name": "amd64-microcode"
        }
    ]
}

Ubuntu:20.04:LTS / amd64-microcode

Package

Name
amd64-microcode
Purl
pkg:deb/ubuntu/amd64-microcode?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20191218.1ubuntu1.3

Affected versions

3.*

3.20181128.1ubuntu2
3.20191021.1ubuntu1
3.20191218.1ubuntu1
3.20191218.1ubuntu1.1
3.20191218.1ubuntu1.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.20191218.1ubuntu1.3",
            "binary_name": "amd64-microcode"
        }
    ]
}

Ubuntu:22.04:LTS / amd64-microcode

Package

Name
amd64-microcode
Purl
pkg:deb/ubuntu/amd64-microcode?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20191218.1ubuntu2.3

Affected versions

3.*

3.20191218.1ubuntu2
3.20191218.1ubuntu2.1
3.20191218.1ubuntu2.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.20191218.1ubuntu2.3",
            "binary_name": "amd64-microcode"
        }
    ]
}

Ubuntu:24.10 / amd64-microcode

Package

Name
amd64-microcode
Purl
pkg:deb/ubuntu/amd64-microcode?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20240116.2+nmu1ubuntu1.1

Affected versions

3.*

3.20231019.1ubuntu2
3.20240116.2+nmu1ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.20240116.2+nmu1ubuntu1.1",
            "binary_name": "amd64-microcode"
        }
    ]
}

Ubuntu:24.04:LTS / amd64-microcode

Package

Name
amd64-microcode
Purl
pkg:deb/ubuntu/amd64-microcode?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20231019.1ubuntu2.1

Affected versions

3.*

3.20230808.1.1ubuntu1
3.20231019.1ubuntu1
3.20231019.1ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.20231019.1ubuntu2.1",
            "binary_name": "amd64-microcode"
        }
    ]
}