CVE-2025-21090
published 2025-08-12CVE-2025-21090: Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via…
PriorityP420medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.14%
4.1th percentile
Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250812.1~deb12u1 (bookworm) | intel-microcode 3.20250812.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv4.04.1MEDIUMCVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.0HIGH
vendor_ubuntu7.2HIGH
vendor_debian4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
intel-microcode vulnerabilities
osv·2025-11-10·CVSS 7.0
CVE-2025-20053 [HIGH] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Barak Gross discovered that some Intel® Xeon® processors with SGX enabled
did not properly handle buffer restrictions. A local authenticated user
could potentially use this issue to escalate their privileges.
(CVE-2025-20053)
Avinash Maddy discovered that some Intel® processors did not properly
isolate or compartmentalize the stream cache mechanisms. A local
authenticated user could potentially use this issue to escalate their
privileges. (CVE-2025-20109)
Joseph Nuzman discovered that some Intel® Xeon® processors did not properly
manage references to active allocate resources. A local authenticated user
could potentially use this issue to cause a denial of service (system
crash). (CVE-2025-21090)
It was discovered that some Intel® Xeon® 6 processors did
GHSA
GHSA-x546-m2vh-46gq: Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of se
ghsa_unreviewed·2025-08-12
CVE-2025-21090 [MEDIUM] CWE-771 GHSA-x546-m2vh-46gq: Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of se
Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access.
OSV
CVE-2025-21090: Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of se
osv·2025-08-12·CVSS 4.1
CVE-2025-21090 [MEDIUM] CVE-2025-21090: Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of se
Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-11-10·CVSS 7.2
CVE-2025-26403 [HIGH] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Barak Gross discovered that some Intel® Xeon® processors with SGX enabled
did not properly handle buffer restrictions. A local authenticated user
could potentially use this issue to escalate their privileges.
(CVE-2025-20053)
Avinash Maddy discovered that some Intel® processors did not properly
isolate or compartmentalize the stream cache mechanisms. A local
authenticated user could potentially use this issue to escalate their
privileges. (CVE-2025-20109)
Joseph Nuzman discovered that some Intel® Xeon® processors did not properly
manage references to active allocate resources. A local authenticated user
could potentially use this issue to cause a denial of service (system
crash). (CVE
Debian
CVE-2025-21090: intel-microcode - Missing reference to active allocated resource for some Intel(R) Xeon(R) process...
vendor_debian·2025·CVSS 4.1
CVE-2025-21090 [MEDIUM] CVE-2025-21090: intel-microcode - Missing reference to active allocated resource for some Intel(R) Xeon(R) process...
Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250812.1~deb12u1)
bullseye: resolved (fixed in 3.20250812.1~deb11u1)
forky: resolved (fixed in 3.20250812.1)
sid: resolved (fixed in 3.20250812.1)
trixie: resolved (fixed in 3.20250812.1~deb13u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-12
Published