Intel closes security holes in laptops, Linux drivers and more
Summary
In August 2021 Intel published updates for several holes in drivers and hardware. The most dangerous was CVE-2021-0084 in the Linux RDMA driver for the X722 and 800 series Ethernet controllers, through which attackers could gain higher privileges. Further holes affected NUC laptop kits, graphics drivers, Optane PMem and the 800 series Ethernet adapters.
Ideas
- Insufficient input validation in kernel drivers enables privilege escalation.
- Hardware manufacturers often deliver driver updates outside the distribution kernel.
- Several holes allowed denial of service via drivers and firmware.
Insights
- Vendor drivers outside the kernel have to be tracked separately.
- Firmware and drivers belong in patch management just like the operating system and applications.
Facts
- Linux drivers 1.3.19 and 1.4.11 closed the RDMA holes.
- For the NUC 8 Extreme laptop kits, version 2.2.0.20 provided a fix.
References
Critique
- The report is a list of advisories without classifying who is realistically affected.
Recommendations
- Keep a list of vendor drivers installed outside the distribution.
- Subscribe to the security advisories of your servers’ hardware manufacturers.
Links to the original source and the Web Archive open in a new tab.