Alerts This Week
Warning Icon 1 1,161
Alerts This Week
Warning Icon 1 1,161

Ubuntu 24.04, 22.04, 20.04: USN-7033-1 critical intel-microcode fixes

ubuntu
Calendar Grey September 25, 2024
Dist Ubuntu Esm H88
Important patches released for addressing the microcode vulnerabilities on Ubuntu systems. Protect your device from possible risks.
Several security issues were fixed in Intel Microcode.

Summary

Several security issues were fixed in Intel Microcode.

Software Description:

- intel-microcode: Processor microcode for Intel CPUs

Details:

It was discovered that some Intel(R) Processors did not properly restrict

access to the Running Average Power Limit (RAPL) interface. This may allow

a local privileged attacker to obtain sensitive information.

(CVE-2024-23984)

It was discovered that some Intel(R) Processors did not properly implement

finite state machines (FSMs) in hardware logic. This may allow a local

privileged attacker to cause a denial of service (system crash).

(CVE-2024-24968)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  intel-microcode                 3.20240910.0ubuntu0.24.04.1

Ubuntu 22.04 LTS
  intel-microcode                 3.20240910.0ubuntu0.22.04.1

Ubuntu 20.04 LTS
  intel-microcode                 3.20240910.0ubuntu0.20.04.1

Ubuntu 18.04 LTS
  intel-microcode                 3.20240910.0ubuntu0.18.04.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  intel-microcode                 3.20240910.0ubuntu0.16.04.1+esm1
                                  Available with Ubuntu Pro

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7033-1

CVE-2024-23984, CVE-2024-24968

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7033-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here