{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2023/cve-2023-38575-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-03T13:44:15Z",
      "generator": {
        "date": "2026-08-03T13:44:14Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2023-38575-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2023-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2023-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-31T18:30:48Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-01T22:30:50Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-08-03T13:44:15Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2023-38575"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "intel-microcode-0:3.20251111.1~deb10u1-.amd64",
                "product": {
                  "name": "intel-microcode-0:3.20251111.1~deb10u1-.amd64",
                  "product_id": "intel-microcode-0:3.20251111.1~deb10u1-.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/intel-microcode@3.20251111.1~deb10u1-?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64",
                "product": {
                  "name": "intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64",
                  "product_id": "intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/intel-microcode@3.20251111.1~deb10u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64"
        },
        "product_reference": "intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "intel-microcode-0:3.20251111.1~deb10u1-.amd64 as a component of Debian 10",
          "product_id": "Debian-10:intel-microcode-0:3.20251111.1~deb10u1-.amd64"
        },
        "product_reference": "intel-microcode-0:3.20251111.1~deb10u1-.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-38575",
      "cwe": {
        "id": "CWE-1303",
        "name": "Non-Transparent Sharing of Microarchitectural Resources"
      },
      "notes": [
        {
          "category": "description",
          "text": "Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64",
          "Debian-10:intel-microcode-0:3.20251111.1~deb10u1-.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-38575"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/05/msg00003.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/05/msg00003.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240405-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20240405-0008/"
        },
        {
          "category": "external",
          "summary": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00982.html",
          "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00982.html"
        }
      ],
      "release_date": "2024-02-14T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-03T11:36:41.765346Z",
          "details": "CVE-2023-38575 is a transient-execution side channel that requires attacker-controlled code to run locally (low privileges) and to manipulate return predictions on the same physical core across context switches, yielding only confidentiality impact with no integrity or availability effect. It does not provide remote code execution or privilege escalation, and practical exploitation hinges on precise same-core co-residency and timing primitives—conditions that are uncommon when untrusted code is not allowed on the host. Given these constraints and the lack of broader impact, this issue can be safely deprioritized relative to remotely exploitable or privilege‑escalation vulnerabilities.",
          "product_ids": [
            "Debian-10:intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64",
            "Debian-10:intel-microcode-0:3.20251111.1~deb10u1-.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Debian-10:intel-microcode-0:3.20251111.1~deb10u1+tuxcare.els1.amd64",
            "Debian-10:intel-microcode-0:3.20251111.1~deb10u1-.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}