CVE-2025-24495Incorrect Initialization of Resource in Intel-microcode

Severity
6.8MEDIUMNVD
OSV5.7
EPSS
0.1%
top 77.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 13
Latest updateMay 27

Description

Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Packages1 packages

debiandebian/intel-microcode< intel-microcode 3.20250512.1~deb12u1 (bookworm)

🔴Vulnerability Details

3
OSV
intel-microcode vulnerabilities2025-05-27
OSV
CVE-2025-24495: Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potenti2025-05-13
GHSA
GHSA-7ppp-wv3j-gg8q: Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potenti2025-05-13

📋Vendor Advisories

3
Ubuntu
Intel Microcode vulnerabilities2025-05-27
Red Hat
microcode_ctl: From CVEorg collector2025-05-13
Debian
CVE-2025-24495: intel-microcode - Incorrect initialization of resource in the branch prediction unit for some Inte...2025