보안 권고문

Intel 제품군 (하드웨어) 2024년 3월 보안 업데이트 권고

개요

 

Intel (https://www.intel.com)에서는 공급한 제품의 취약점을 해결하는 보안 업데이트를 발표하였습니다. 해당하는 제품 사용자는 최신 버전으로 업데이트하시기 바랍니다.

 

대상 제품

 

Generation Intel® Xeon® Scalable processors 4세대

Generation Intel® Xeon® Platinum processors 4세대

Generation Intel® Xeon® Gold processors 4세대

Generation Intel® Xeon® Silver processors 4세대

Generation Intel® Xeon® Bronze processors 4세대

Intel® Xeon® CPU Max Series processors 

13th Generation Intel® Core™ Processor Family 

14th Generation Intel® Core™ Processor Family 

Intel® Pentium® Gold Processor Family 

Intel® Celeron® Processor Family Intel Pentium Processor G7400/G7400T 

Intel® Xeon® E processor family 

Intel® Xeon® CPU Max Series processors (High Bandwidth Memory HBM) 

Generation Intel® Xeon® Scalable processors 4세대

Generation Intel® Xeon® Scalable processors 5세대

Generation Intel® Xeon® Platinum processors 4세대

Generation Intel® Xeon® Gold Processors 4세대

Generation Intel® Xeon® Silver Processor 4세대

Generation Intel® Xeon®Bronze Processor 4세대

Intel® Xeon® W workstation processors

Intel® Core™ Processor N series

Intel® Processor N-series

Intel Atom® Processor X Series

 

해결된 취약점

 

Intel® SGX 또는 Intel® TDX를 사용할 때 일부 4세대 Intel® Xeon® 프로세서에서 부적절한 액세스 제어가 포함된 온칩 디버그 및 테스트 인터페이스로 인해 발생하는 로컬 액세스를 통한 권한 상승 취약점 (CVE-2023-32666)

일부 Intel® 프로세서의 컨텍스트 간에 수익 예측 변수 목표를 불투명하게 공유 시 발생하는 정보 공개 취약점 (CVE-2023-38575)

일부 Intel® 프로세서에 대한 bus lock regulator의 보호 메커니즘 오류로 인해 발생하는 서비스 거부 취약점 (CVE-2023-39368)

 

취약점 패치

 

2024년 3월 12일 업데이트를 통해 취약점 패치가 제공되었습니다. 취약점 패치에 대한 보다 자세한 사항은 제품별 참고 사이트 문서의 “Recommendation” 섹션을 참고하시기 바랍니다.

 

참고 사이트

 

[1] 4th Gen Intel® Xeon® Processor Advisory

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00986.html

[2] 2024.1 IPU – Intel® Processor Return Predictions Advisory

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00982.html

[3] 2024.1 IPU – Intel® Processor Bus Lock Advisory

https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00972.html

[4] Affected Processors: Guidance for Security Issues on Intel® Processors

https://www.intel.com/content/www/us/en/developer/topic-technology/software-security-guidance/processors-affected-consolidated-product-cpu-model.html