CVE-2025-22889Improper Handling of Overlap Between Protected Memory Ranges in Intel-microcode

Severity
7.0HIGHNVD
EPSS
0.0%
top 95.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateNov 10

Description

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20250812.1~deb12u1 (bookworm)

🔴Vulnerability Details

3
OSV
intel-microcode vulnerabilities2025-11-10
OSV
CVE-2025-22889: Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may allow a privileged user to po2025-08-12
GHSA
GHSA-x9p4-6h68-vm5q: Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may allow a privileged user to po2025-08-12

📋Vendor Advisories

2
Ubuntu
Intel Microcode vulnerabilities2025-11-10
Debian
CVE-2025-22889: intel-microcode - Improper handling of overlap between protected memory ranges for some Intel(R) X...2025