Alerts This Week
Warning Icon 1 1,220
Alerts This Week
Warning Icon 1 1,220

Debian LTS: DLA-4002-1 critical: intel-microcode local access issues

debian lts
Calendar Grey December 23, 2024
Dist Debian Esm H88
Debian LTS Advisory DLA-4003-1 delivers essential patches for linux-image, addressing vulnerabilities that may lead to unauthorized access.
A microcode update has been released for Intel processors, addressing multiple vulnerabilties which potentially could cause local privileged escalation or local DoS

Summary

CVE-2024-23918

Improper conditions check in some Intel(R) Xeon(R) processor memory controller
configurations when using Intel(R) SGX may allow a privileged user to
potentially enable escalation of privilege via local access. (INTEL-SA-01079)

CVE-2024-21853

Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th
Generation Intel(R) Xeon(R) Processors may allow an authorized user to
potentially enable denial of service via local access. (INTEL-SA-01101)

CVE-2024-21820

Incorrect default permissions in some Intel(R) Xeon(R) processor memory
controller configurations when using Intel(R) SGX may allow a privileged user
to potentially enable escalation of privilege via local access.
(INTEL-SA-01079)

CVE-2024-23984 (already adressed in a previous upload, this upload adds more processor models.)

Observable discrepancy in RAPL interface for some Intel(R) Processors may allow

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: intel-microcode
Version: 3.20241112.1~deb11u1
CVE ID: CVE-2024-23918 CVE-2024-21853 CVE-2024-21820 CVE-2024-23984
Debian Bug: 1087532

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here