Debian Intel-Microcode vulnerabilities
90 known vulnerabilities affecting debian/intel-microcode.
Total CVEs
90
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH21MEDIUM66LOW3
Vulnerabilities
Page 2 of 5
CVE-2018-3640P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20180703.1 (bookworm)2018
CVE-2018-3640 [MEDIUM] CVE-2018-3640: intel-microcode - Systems with microprocessors utilizing speculative execution and that perform sp...
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resol
debian
CVE-2025-22840P4MEDIUMCVSS 5.3fixed in intel-microcode 3.20250812.1~deb12u1 (bookworm)2025
CVE-2025-22840 [MEDIUM] CVE-2025-22840: intel-microcode - Sequence of processor instructions leads to unexpected behavior for some Intel(R...
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Xeon(R) 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access
Scope: local
bookworm: resolved (fixed in 3.20250812.1~deb12u1)
bullseye: resolved (fixed in 3.20250812.1~deb11u1)
forky: resolved (fixed in 3.20250812
debian
CVE-2025-24305P4HIGHCVSS 7.0fixed in intel-microcode 3.20250812.1~deb12u1 (bookworm)2025
CVE-2025-24305 [HIGH] CVE-2025-24305: intel-microcode - Insufficient control flow management in the Alias Checking Trusted Module (ACTM)...
Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20250812.1~deb12u1)
bullseye: resolved (fixed in 3.20250812.1~deb11u1)
forky: resolved (fixed in
debian
CVE-2024-21820P4HIGHCVSS 8.5fixed in intel-microcode 3.20241112.1~deb12u1 (bookworm)2024
CVE-2024-21820 [HIGH] CVE-2024-21820: intel-microcode - Incorrect default permissions in some Intel(R) Xeon(R) processor memory controll...
Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20241112.1~deb12u1)
bullseye: resolved (fixed in 3.20241112.1~deb11u1)
forky: resolved (fixed in 3.202
debian
CVE-2018-3620P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20180703.1 (bookworm)2018
CVE-2018-3620 [MEDIUM] CVE-2018-3620: intel-microcode - Systems with microprocessors utilizing speculative execution and address transla...
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.
Scope: local
bookworm: resolved (fixed in 3.20180703.1)
bullseye: resolved (fixed in 3.20180703.1)
for
debian
CVE-2022-40982P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20230808.1~deb12u1 (bookworm)2022
CVE-2022-40982 [MEDIUM] CVE-2022-40982: intel-microcode - Information exposure through microarchitectural state after transient execution ...
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20230808.1~deb12u1)
bullseye: resolved (fixed in 3.20230808.1~deb11u1)
forky
debian
CVE-2025-32086P4MEDIUMCVSS 4.5fixed in intel-microcode 3.20250812.1~deb12u1 (bookworm)2025
CVE-2025-32086 [MEDIUM] CVE-2025-32086: intel-microcode - Improperly implemented security check for standard in the DDRIO configuration fo...
Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20250812.1~deb12u1)
bullseye: resolved (fixed in 3.20250812.1~deb
debian
CVE-2022-21123P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21123 [MEDIUM] CVE-2022-21123: intel-microcode - Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may...
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed in 3.20220510.1)
t
debian
CVE-2022-21166P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21166 [MEDIUM] CVE-2022-21166: intel-microcode - Incomplete cleanup in specific special register write operations for some Intel(...
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed i
debian
CVE-2023-39368P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20240312.1~deb12u1 (bookworm)2023
CVE-2023-39368 [MEDIUM] CVE-2023-39368: intel-microcode - Protection mechanism failure of bus lock regulator for some Intel(R) Processors ...
Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky: resolved (fixed in 3.20240312.1)
sid: resolved (fixed in 3.202
debian
CVE-2022-21125P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21125 [MEDIUM] CVE-2022-21125: intel-microcode - Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processor...
Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed in 3.20220510
debian
CVE-2019-11135P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20191112.1 (bookworm)2019
CVE-2019-11135 [MEDIUM] CVE-2019-11135: intel-microcode - TSX Asynchronous Abort condition on some CPUs utilizing speculative execution ma...
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Scope: local
bookworm: resolved (fixed in 3.20191112.1)
bullseye: resolved (fixed in 3.20191112.1)
forky: resolved (fixed in 3.20191112.1)
sid: resolved (fixed in 3.
debian
CVE-2022-21216P4HIGHCVSS 7.5fixed in intel-microcode 3.20230214.1 (bookworm)2022
CVE-2022-21216 [HIGH] CVE-2022-21216: intel-microcode - Insufficient granularity of access control in out-of-band management in some Int...
Insufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a privileged user to potentially enable escalation of privilege via adjacent network access.
Scope: local
bookworm: resolved (fixed in 3.20230214.1)
bullseye: resolved (fixed in 3.20230214.1~deb11u1)
forky: resolved (fixed i
debian
CVE-2024-24853P4HIGHCVSS 7.3fixed in intel-microcode 3.20240813.1~deb12u1 (bookworm)2024
CVE-2024-24853 [HIGH] CVE-2024-24853: intel-microcode - Incorrect behavior order in transition between executive monitor and SMI transfe...
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20240813.1~deb12u1)
bullseye: resolved (fixed in 3.20240813.1~deb11u1)
forky: resolved (fixed in 3.20
debian
CVE-2022-21127P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21127 [MEDIUM] CVE-2022-21127: intel-microcode - Incomplete cleanup in specific special register read operations for some Intel(R...
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved (fixed in
debian
CVE-2022-41804P4HIGHCVSS 7.2fixed in intel-microcode 3.20230808.1~deb12u1 (bookworm)2022
CVE-2022-41804 [HIGH] CVE-2022-41804: intel-microcode - Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) X...
Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20230808.1~deb12u1)
bullseye: resolved (fixed in 3.20230808.1~deb11u1)
forky: resolved (fixed in 3.20230808.1)
sid: resolved (
debian
CVE-2023-28746P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20240312.1~deb12u1 (bookworm)2023
CVE-2023-28746 [MEDIUM] CVE-2023-28746: intel-microcode - Information exposure through microarchitectural state after transient execution ...
Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky:
debian
CVE-2018-12130P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12130 [MEDIUM] CVE-2018-12130: intel-microcode - Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some micro...
Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-in
debian
CVE-2023-47855P4MEDIUMCVSS 6.0fixed in intel-microcode 3.20240514.1~deb12u1 (bookworm)2023
CVE-2023-47855 [MEDIUM] CVE-2023-47855: intel-microcode - Improper input validation in some Intel(R) TDX module software before version 1....
Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20240514.1~deb12u1)
bullseye: resolved (fixed in 3.20240514.1~deb11u1)
forky: resolved (fixed in 3.20240514.1)
sid: resolved (fixe
debian
CVE-2022-33196P4HIGHCVSS 7.2fixed in intel-microcode 3.20230214.1 (bookworm)2022
CVE-2022-33196 [HIGH] CVE-2022-33196: intel-microcode - Incorrect default permissions in some memory controller configurations for some ...
Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20230214.1)
bullseye: resolved (fixed in 3.20230214.1~deb11u1)
f
debian