CVE-2025-24495
published 2025-05-13CVE-2025-24495: Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially…
PriorityP421medium5.6CVSS 3.1
AVLACHPRLUINSCCHINAN
EPSS
0.17%
6.6th percentile
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | intel-microcode | < intel-microcode 3.20250512.1~deb12u1 (bookworm) | intel-microcode 3.20250512.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2025-05-27·CVSS 5.6
CVE-2024-45332 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtai
Red Hat
microcode_ctl: From CVEorg collector
vendor_redhat·2025-05-13·CVSS 6.8
CVE-2025-24495 [MEDIUM] CWE-1419 microcode_ctl: From CVEorg collector
microcode_ctl: From CVEorg collector
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
A flaw was found in the Branch Prediction Unit (BPU) of Intel's Lion Core CPUs that make it possible for an attacker to bypass Indirect Branch Predictor Barrier (IBPB) protections. By employing branch predictor training techniques as described in the "Training Solo" publication, an attacker with local privileges could use this bypass to exfiltrate sensitive data from an affected system, including from host hypervisors or neighboring guests in virtualized environments.
Statement: This vulnerability was disclosed as part of the "Training Solo" report. T
Debian
CVE-2025-24495: intel-microcode - Incorrect initialization of resource in the branch prediction unit for some Inte...
vendor_debian·2025·CVSS 6.8
CVE-2025-24495 [MEDIUM] CVE-2025-24495: intel-microcode - Incorrect initialization of resource in the branch prediction unit for some Inte...
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in 3.20250512.1)
trixie: resolved (fixed in 3.20250512.1)
OSV
intel-microcode vulnerabilities
osv·2025-05-27·CVSS 5.7
CVE-2024-28956 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Sander Wiebing and Cristiano Giuffrida discovered that some Intel®
Processors did not properly handle data in Shared Microarchitectural
Structures during Transient Execution. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2024-28956)
It was discovered that some Intel® Processors did not properly handle
prediction calculations. An authenticated attacker could possibly use this
issue to obtain sensitive information. (CVE-2024-43420, CVE-2024-45332,
CVE-2025-20623)
It was discovered that some Intel® Processors did not properly initialize
resources in the branch prediction unit. An authenticated attacker could
possibly use this issue to obtain sensitive information. (CVE-2025-20012,
CVE-2025-24495)
Michal Raviv
OSV
CVE-2025-24495: Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potenti
osv·2025-05-13·CVSS 6.8
CVE-2025-24495 [MEDIUM] CVE-2025-24495: Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potenti
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
GHSA
GHSA-7ppp-wv3j-gg8q: Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potenti
ghsa_unreviewed·2025-05-13
CVE-2025-24495 [MEDIUM] GHSA-7ppp-wv3j-gg8q: Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potenti
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-13
Published