CVE-2023-38575
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2023-38575) was discovered in Intel Processors involving non-transparent sharing of return predictor targets between contexts. This vulnerability was publicly disclosed on March 12, 2024, affecting various Intel Processor models. The vulnerability allows an authorized user to potentially enable information disclosure through local access (Intel Advisory, NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium), with a vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. This indicates that the vulnerability requires local access, low attack complexity, and low privileges, with no user interaction needed. The scope is unchanged, and the impact is limited to high confidentiality breach with no impact on integrity or availability. The vulnerability is classified under CWE-1303 (Non-Transparent Sharing of Microarchitectural Resources) (Intel Advisory, Red Hat).

Impact

The vulnerability can lead to information disclosure, potentially impacting the data confidentiality of the targeted host. When successfully exploited, it allows an authorized user to access sensitive information through local access. The high confidentiality impact suggests that the attacker could gain access to significant amounts of sensitive data (Red Hat).

Exploitability

The vulnerability requires local access to the system and low privileges for exploitation. The attack complexity is rated as low, indicating that the attack can be performed with minimal conditions that need to be satisfied for exploitation. No user interaction is required for the exploit to succeed (Intel Advisory).

Mitigation and workarounds

Intel has released microcode updates to mitigate this vulnerability. Users of affected Intel Processors are recommended to update to the latest version firmware provided by their system manufacturer. For non-Intel Software Guard Extension (SGX) customers, the microcode patch can be OS loadable. For Intel SGX enabled systems, Intel recommends updating the microcode located in platform flash designated by firmware interface table (FIT) entry point1 (Intel Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Alpine

Fixed

edge

intel-ucode: 20240312-r0

Fixed

v3.18

intel-ucode: 20240813-r0

Fixed

v3.19

intel-ucode: 20240312-r0

Fixed

v3.20

intel-ucode: 20240312-r0

Fixed

v3.21

intel-ucode: 20240312-r0

Fixed

v3.22

intel-ucode: 20240312-r0

Fixed

v3.23

intel-ucode: 20240312-r0

Fixed

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management