Debian Intel-Microcode vulnerabilities
90 known vulnerabilities affecting debian/intel-microcode.
Total CVEs
90
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH21MEDIUM66LOW3
Vulnerabilities
Page 3 of 5
CVE-2020-24513P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20210608.1 (bookworm)2020
CVE-2020-24513 [MEDIUM] CVE-2020-24513: intel-microcode - Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors...
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20210608.1)
bullseye: resolved (fixed in 3.20210608.1)
forky: resolved (fixed in 3.20210608.1)
sid: resolved (fixed in 3.20210608.1)
trixi
debian
CVE-2018-12127P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12127 [MEDIUM] CVE-2018-12127: intel-microcode - Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microproc...
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-inform
debian
CVE-2018-12126P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2018
CVE-2018-12126 [MEDIUM] CVE-2018-12126: intel-microcode - Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some mic...
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-
debian
CVE-2020-24511P4MEDIUMCVSS 6.5fixed in intel-microcode 3.20210608.1 (bookworm)2020
CVE-2020-24511 [MEDIUM] CVE-2020-24511: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow an ...
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20210608.1)
bullseye: resolved (fixed in 3.20210608.1)
forky: resolved (fixed in 3.20210608.1)
sid: resolved (fixed in 3.20210608.1)
trixie: resolved (f
debian
CVE-2024-28956P4MEDIUMCVSS 5.7fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2024
CVE-2024-28956 [MEDIUM] CVE-2024-28956: intel-microcode - Exposure of Sensitive Information in Shared Microarchitectural Structures during...
Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (f
debian
CVE-2019-11091P4MEDIUMCVSS 5.6fixed in intel-microcode 3.20190514.1 (bookworm)2019
CVE-2019-11091 [MEDIUM] CVE-2019-11091: intel-microcode - Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory ...
Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents
debian
CVE-2021-33120P4MEDIUMCVSS 5.4fixed in intel-microcode 3.20220207.1 (bookworm)2021
CVE-2021-33120 [MEDIUM] CVE-2021-33120: intel-microcode - Out of bounds read under complex microarchitectural condition in memory subsyste...
Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.
Scope: local
bookworm: resolved (fixed in 3.20220207.1)
bullseye: resolved (fixed in 3.20220207.1~deb11u1)
forky: resolve
debian
CVE-2023-38575P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20240312.1~deb12u1 (bookworm)2023
CVE-2023-38575 [MEDIUM] CVE-2023-38575: intel-microcode - Non-transparent sharing of return predictor targets between contexts in some Int...
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky: resolved (fixed in 3.20240312.1)
sid: resolved
debian
CVE-2024-45332P4MEDIUMCVSS 5.7fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2024
CVE-2024-45332 [MEDIUM] CVE-2024-45332: intel-microcode - Exposure of sensitive information caused by shared microarchitectural predictor ...
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: reso
debian
CVE-2025-20623P4MEDIUMCVSS 5.7fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2025
CVE-2025-20623 [MEDIUM] CVE-2025-20623: intel-microcode - Exposure of sensitive information caused by shared microarchitectural predictor ...
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Core™ processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixe
debian
CVE-2024-43420P4MEDIUMCVSS 5.7fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2024
CVE-2024-43420 [MEDIUM] CVE-2024-43420: intel-microcode - Exposure of sensitive information caused by shared microarchitectural predictor ...
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~d
debian
CVE-2020-0543P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20200609.1 (bookworm)2020
CVE-2020-0543 [MEDIUM] CVE-2020-0543: intel-microcode - Incomplete cleanup from specific special register read operations in some Intel(...
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20200609.1)
bullseye: resolved (fixed in 3.20200609.1)
forky: resolved (fixed in 3.20200609.1)
sid: resolved (fixed in 3.202006
debian
CVE-2024-24980P4MEDIUMCVSS 6.9fixed in intel-microcode 3.20240813.1~deb12u1 (bookworm)2024
CVE-2024-24980 [MEDIUM] CVE-2024-24980: intel-microcode - Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(...
Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20240813.1~deb12u1)
bullseye: resolved (fixed in 3.20240813.1~deb11u1)
forky: resolved (fixed in 3.20240813.1)
sid: resolved (fi
debian
CVE-2024-39279P4MEDIUMCVSS 6.8fixed in intel-microcode 3.20250211.1~deb12u1 (bookworm)2024
CVE-2024-39279 [MEDIUM] CVE-2024-39279: intel-microcode - Insufficient granularity of access control in UEFI firmware in some Intel(R) pro...
Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: resolved (fixed in 3.
debian
CVE-2025-24495P4MEDIUMCVSS 6.8fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2025
CVE-2025-24495 [MEDIUM] CVE-2025-24495: intel-microcode - Incorrect initialization of resource in the branch prediction unit for some Inte...
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
debian
CVE-2023-22655P4MEDIUMCVSS 6.1fixed in intel-microcode 3.20240312.1~deb12u1 (bookworm)2023
CVE-2023-22655 [MEDIUM] CVE-2023-22655: intel-microcode - Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Pro...
Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky: resolved (fixed
debian
CVE-2020-0549P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20200609.1 (bookworm)2020
CVE-2020-0549 [MEDIUM] CVE-2020-0549: intel-microcode - Cleanup errors in some data cache evictions for some Intel(R) Processors may all...
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20200609.1)
bullseye: resolved (fixed in 3.20200609.1)
forky: resolved (fixed in 3.20200609.1)
sid: resolved (fixed in 3.20200609.1)
trixie: resolve
debian
CVE-2020-0548P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20200609.1 (bookworm)2020
CVE-2020-0548 [MEDIUM] CVE-2020-0548: intel-microcode - Cleanup errors in some Intel(R) Processors may allow an authenticated user to po...
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20200609.1)
bullseye: resolved (fixed in 3.20200609.1)
forky: resolved (fixed in 3.20200609.1)
sid: resolved (fixed in 3.20200609.1)
trixie: resolved (fixed in 3.20200609.1)
debian
CVE-2020-8698P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20201110.1 (bookworm)2020
CVE-2020-8698 [MEDIUM] CVE-2020-8698: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow an ...
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20201110.1)
bullseye: resolved (fixed in 3.20201110.1)
forky: resolved (fixed in 3.20201110.1)
sid: resolved (fixed in 3.20201110.1)
trixie: resolved (fix
debian
CVE-2020-8696P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20201110.1 (bookworm)2020
CVE-2020-8696 [MEDIUM] CVE-2020-8696: intel-microcode - Improper removal of sensitive information before storage or transfer in some Int...
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20201110.1)
bullseye: resolved (fixed in 3.20201110.1)
forky: resolved (fixed in 3.20201110.1)
sid: resolved (fixed in 3.202
debian