CVE-2025-20103
published 2025-05-13CVE-2025-20103: Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of…
PriorityP420medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.14%
3.9th percentile
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250512.1~deb12u1 (bookworm) | intel-microcode 3.20250512.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv4.05.7MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2025-05-27·CVSS 5.7
CVE-2024-28956 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2025-20012,
CVE-2025-24495)
Michal Raviv
GHSA
GHSA-5qwv-r493-496q: Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial
ghsa_unreviewed·2025-05-13
CVE-2025-20103 [MEDIUM] CWE-410 GHSA-5qwv-r493-496q: Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
OSV
CVE-2025-20103: Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial
osv·2025-05-13·CVSS 5.7
CVE-2025-20103 [MEDIUM] CVE-2025-20103: Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-05-27·CVSS 5.6
CVE-2024-45332 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtai
Red Hat
microcode_ctl: Insufficient resource pool in the core management mechanism
vendor_redhat·2025-05-13·CVSS 5.7
CVE-2025-20103 [MEDIUM] CWE-410 microcode_ctl: Insufficient resource pool in the core management mechanism
microcode_ctl: Insufficient resource pool in the core management mechanism
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Package: microcode_ctl (Red Hat Enterprise Linux 10) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 6) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 7) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 8) - Fix deferred
Package: microcode_ctl (Red Hat Enterprise Linux 9) - Fix deferred
Debian
CVE-2025-20103: intel-microcode - Insufficient resource pool in the core management mechanism for some Intel(R) Pr...
vendor_debian·2025·CVSS 5.7
CVE-2025-20103 [MEDIUM] CVE-2025-20103: intel-microcode - Insufficient resource pool in the core management mechanism for some Intel(R) Pr...
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in 3.20250512.1)
trixie: resolved (fixed in 3.20250512.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-13
Published