CVE-2025-20109
published 2025-08-12CVE-2025-20109: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable…
PriorityP337high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
0.14%
3.7th percentile
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250812.1~deb12u1 (bookworm) | intel-microcode 3.20250812.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.3HIGH
vendor_debian7.3HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2025-11-10·CVSS 7.0
CVE-2025-20053 [HIGH] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Barak Gross discovered that some Intel® Xeon® processors with SGX enabled
did not properly handle buffer restrictions. A local authenticated user
could potentially use this issue to escalate their privileges.
(CVE-2025-20053)
Avinash Maddy discovered that some Intel® processors did not properly
isolate or compartmentalize the stream cache mechanisms. A local
authenticated user could potentially use this issue to escalate their
privileges. (CVE-2025-20109)
Joseph Nuzman discovered that some Intel® Xeon® processors did not properly
manage references to active allocate resources. A local authenticated user
could potentially use this issue to cause a denial of service (system
crash). (CVE-2025-21090)
It was discovered that some Intel® Xeon® 6 processors did
GHSA
GHSA-3cpg-9r3v-qv5v: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially e
ghsa_unreviewed·2025-08-12
CVE-2025-20109 [HIGH] CWE-653 GHSA-3cpg-9r3v-qv5v: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially e
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
OSV
CVE-2025-20109: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially e
osv·2025-08-12·CVSS 7.3
CVE-2025-20109 [HIGH] CVE-2025-20109: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially e
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-11-10·CVSS 7.2
CVE-2025-26403 [HIGH] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Barak Gross discovered that some Intel® Xeon® processors with SGX enabled
did not properly handle buffer restrictions. A local authenticated user
could potentially use this issue to escalate their privileges.
(CVE-2025-20053)
Avinash Maddy discovered that some Intel® processors did not properly
isolate or compartmentalize the stream cache mechanisms. A local
authenticated user could potentially use this issue to escalate their
privileges. (CVE-2025-20109)
Joseph Nuzman discovered that some Intel® Xeon® processors did not properly
manage references to active allocate resources. A local authenticated user
could potentially use this issue to cause a denial of service (system
crash). (CVE
Debian
CVE-2025-20109: intel-microcode - Improper Isolation or Compartmentalization in the stream cache mechanism for som...
vendor_debian·2025·CVSS 7.3
CVE-2025-20109 [HIGH] CVE-2025-20109: intel-microcode - Improper Isolation or Compartmentalization in the stream cache mechanism for som...
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20250812.1~deb12u1)
bullseye: resolved (fixed in 3.20250812.1~deb11u1)
forky: resolved (fixed in 3.20250812.1)
sid: resolved (fixed in 3.20250812.1)
trixie: resolved (fixed in 3.20250812.1~deb13u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-12
Published