Lucene search

K
redosRedosROS-20240902-03
HistorySep 02, 2024 - 12:00 a.m.

ROS-20240902-03

2024-09-0200:00:00
redos.red-soft.ru
3
intel processor
firmware vulnerability
redundant prefixes
privilege escalation
sensitive information
denial of service
rep" instruction
unix

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

Intel processor firmware vulnerability is related to errors in interpretation of redundant prefixes.
of redundant prefixes. Exploitation of the vulnerability could allow an attacker to escalate privileges (from
third to zero ring of protection (CPL0)), gain access to sensitive information, or cause a denial of service when executing the โ€œREPโ€ instruction.
Denial of service when executing a โ€œREP MOVSBโ€ instruction encoded with the redundant โ€œREXโ€ prefix

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64linux-firmware<ย 20240709-1UNKNOWN

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.3

Confidence

Low