Intel Product Security Update Advisory

Overview

 

An update has been released to address vulnerabilities in Intel Products. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-23495, CVE-2024-23491

  • Intel® Distribution for GDB software versions: ~ 2024.0.1 (excluded)
  • Intel® oneAPI Base Toolkit software versions: ~ 2024.1 (excluded)

 

 

Resolved Vulnerabilities

 

Vulnerability in Intel® Distribution for GDB software with incorrect default privileges, potentially allowing an authenticated user to escalate privileges via local access (CVE-2024-23495)

Vulnerability in Intel® Distribution for GDB software with an uncontrolled search path that could potentially allow an authenticated user to escalate privileges via local access (CVE-2024-23491)

 

Vulnerability Patches

The following product-specific Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-23495, CVE-2024-23491

  • Intel® Distribution for GDB software version: 2024.0.1 or later version
  • Intel® oneAPI Base Toolkit software version: 2024.1 or later version

 

 

References
 

[1] CVE-2024-23495 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23495

[2] CVE-2024-23491 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-23491

[3] Intel® Distribution for GDB Software Advisory

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01075.html