cbcvebase.
CVE-2024-28956
published 2025-05-13

CVE-2024-28956: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated…

PriorityP423medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.37%
29.7th percentile
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianintel-microcode< intel-microcode 3.20250512.1~deb12u1 (bookworm)intel-microcode 3.20250512.1~deb12u1 (bookworm)
debianlinux< intel-microcode 3.20250512.1~deb12u1 (bookworm)intel-microcode 3.20250512.1~deb12u1 (bookworm)
debianlinux-6.1< intel-microcode 3.20250512.1~deb12u1 (bookworm)intel-microcode 3.20250512.1~deb12u1 (bookworm)
debianxen< intel-microcode 3.20250512.1~deb12u1 (bookworm)intel-microcode 3.20250512.1~deb12u1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
xenxen>= 0 < 4.17.5+72-g01140da4e8-14.17.5+72-g01140da4e8-1
xenxen>= 0 < 4.20.2+7-g1badcf5035-0+deb13u14.20.2+7-g1badcf5035-0+deb13u1
xenxen>= 0 < 4.20.2+7-g1badcf5035-14.20.2+7-g1badcf5035-1

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv4.05.7MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.