Debian Intel-Microcode vulnerabilities
90 known vulnerabilities affecting debian/intel-microcode.
Total CVEs
90
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH21MEDIUM66LOW3
Vulnerabilities
Page 4 of 5
CVE-2020-8695P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20201110.1 (bookworm)2020
CVE-2020-8695 [MEDIUM] CVE-2020-8695: intel-microcode - Observable discrepancy in the RAPL interface for some Intel(R) Processors may al...
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20201110.1)
bullseye: resolved (fixed in 3.20201110.1)
forky: resolved (fixed in 3.20201110.1)
sid: resolved (fixed in 3.20201110.1)
trixie: resolved (
debian
CVE-2022-21151P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220510.1 (bookworm)2022
CVE-2022-21151 [MEDIUM] CVE-2022-21151: intel-microcode - Processor optimization removal or modification of security-critical code for som...
Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220510.1)
bullseye: resolved (fixed in 3.20220510.1~deb11u1)
forky: resolved (fixed in 3.20220510.1)
sid: resolved
debian
CVE-2021-0145P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220207.1 (bookworm)2021
CVE-2021-0145 [MEDIUM] CVE-2021-0145: intel-microcode - Improper initialization of shared resources in some Intel(R) Processors may allo...
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220207.1)
bullseye: resolved (fixed in 3.20220207.1~deb11u1)
forky: resolved (fixed in 3.20220207.1)
sid: resolved (fixed in 3.20220207.1)
trixie:
debian
CVE-2022-21233P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220809.1 (bookworm)2022
CVE-2022-21233 [MEDIUM] CVE-2022-21233: intel-microcode - Improper isolation of shared resources in some Intel(R) Processors may allow a p...
Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220809.1)
bullseye: resolved (fixed in 3.20230214.1~deb11u1)
forky: resolved (fixed in 3.20220809.1)
sid: resolved (fixed in 3.20220809.1)
trixie: resolve
debian
CVE-2021-33117P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220207.1 (bookworm)2021
CVE-2021-33117 [MEDIUM] CVE-2021-33117: intel-microcode - Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Proces...
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20220207.1)
bullseye: resolved (fixed in 3.20220207.1~deb11u1)
forky: resolved (fixed in 3.20220207.1)
sid: resolv
debian
CVE-2019-14607P4MEDIUMCVSS 5.3fixed in intel-microcode 3.20191115.1 (bookworm)2019
CVE-2019-14607 [MEDIUM] CVE-2019-14607: intel-microcode - Improper conditions check in multiple Intel® Processors may allow an authenticat...
Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial escalation of privilege, denial of service and/or information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20191115.1)
bullseye: resolved (fixed in 3.20191115.1)
forky: resolved (fixed in 3.20191115.1)
sid: resol
debian
CVE-2024-36293P4MEDIUMCVSS 6.8fixed in intel-microcode 3.20250211.1~deb12u1 (bookworm)2024
CVE-2024-36293 [MEDIUM] CVE-2024-36293: intel-microcode - Improper access control in the EDECCSSA user leaf function for some Intel(R) Pro...
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: re
debian
CVE-2024-39355P4MEDIUMCVSS 5.7fixed in intel-microcode 3.20250211.1~deb12u1 (bookworm)2024
CVE-2024-39355 [MEDIUM] CVE-2024-39355: intel-microcode - Improper handling of physical or environmental conditions in some Intel(R) Proce...
Improper handling of physical or environmental conditions in some Intel(R) Processors may allow an authenticated user to enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: resolved (fixed in 3.20250211.1)
t
debian
CVE-2025-20103P4MEDIUMCVSS 5.7fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2025
CVE-2025-20103 [MEDIUM] CVE-2025-20103: intel-microcode - Insufficient resource pool in the core management mechanism for some Intel(R) Pr...
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in
debian
CVE-2024-31157P4MEDIUMCVSS 6.8fixed in intel-microcode 3.20250211.1~deb12u1 (bookworm)2024
CVE-2024-31157 [MEDIUM] CVE-2024-31157: intel-microcode - Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Pr...
Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: resolved (fixed in
debian
CVE-2024-23984P4MEDIUMCVSS 6.8fixed in intel-microcode 3.20240910.1~deb12u1 (bookworm)2024
CVE-2024-23984 [MEDIUM] CVE-2024-23984: intel-microcode - Observable discrepancy in RAPL interface for some Intel(R) Processors may allow ...
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240910.1~deb12u1)
bullseye: resolved (fixed in 3.20240910.1~deb11u1)
forky: resolved (fixed in 3.20240910.1)
sid: resolved (fixed in 3.20240910.1)
trix
debian
CVE-2025-20054P4MEDIUMCVSS 6.8fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2025
CVE-2025-20054 [MEDIUM] CVE-2025-20054: intel-microcode - Uncaught exception in the core management mechanism for some Intel(R) Processors...
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in 3.202505
debian
CVE-2025-21090P4MEDIUMCVSS 4.1fixed in intel-microcode 3.20250812.1~deb12u1 (bookworm)2025
CVE-2025-21090 [MEDIUM] CVE-2025-21090: intel-microcode - Missing reference to active allocated resource for some Intel(R) Xeon(R) process...
Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20250812.1~deb12u1)
bullseye: resolved (fixed in 3.20250812.1~deb11u1)
forky: resolved (fixed in 3.20250812.1)
sid: resolved (fixed in 3.202
debian
CVE-2023-43490P4MEDIUMCVSS 5.3fixed in intel-microcode 3.20240312.1~deb12u1 (bookworm)2023
CVE-2023-43490 [MEDIUM] CVE-2023-43490: intel-microcode - Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D ...
Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20240312.1~deb12u1)
bullseye: resolved (fixed in 3.20240312.1~deb11u1)
forky: resolved (fixed in 3.20240312.1)
sid
debian
CVE-2024-28047P4MEDIUMCVSS 6.8fixed in intel-microcode 3.20250211.1~deb12u1 (bookworm)2024
CVE-2024-28047 [MEDIUM] CVE-2024-28047: intel-microcode - Improper input validation in UEFI firmware for some Intel(R) Processors may allo...
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20250211.1~deb12u1)
bullseye: resolved (fixed in 3.20250211.1~deb11u1)
forky: resolved (fixed in 3.20250211.1)
sid: resolved (fixed in 3.20250211.1)
tr
debian
CVE-2025-20012P4MEDIUMCVSS 4.1fixed in intel-microcode 3.20250512.1~deb12u1 (bookworm)2025
CVE-2025-20012 [MEDIUM] CVE-2025-20012: intel-microcode - Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an u...
Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable information disclosure via physical access.
Scope: local
bookworm: resolved (fixed in 3.20250512.1~deb12u1)
bullseye: resolved (fixed in 3.20250512.1~deb11u1)
forky: resolved (fixed in 3.20250512.1)
sid: resolved (fixed in 3.20250512.1)
debian
CVE-2024-25939P4MEDIUMCVSS 6.7fixed in intel-microcode 3.20240813.1~deb12u1 (bookworm)2024
CVE-2024-25939 [MEDIUM] CVE-2024-25939: intel-microcode - Mirrored regions with different values in 3rd Generation Intel(R) Xeon(R) Scalab...
Mirrored regions with different values in 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20240813.1~deb12u1)
bullseye: resolved (fixed in 3.20240813.1~deb11u1)
forky: resolved (fixed in 3.20240813.1)
sid: resolved (fixed in
debian
CVE-2021-0127P4MEDIUMCVSS 5.5fixed in intel-microcode 3.20220207.1 (bookworm)2021
CVE-2021-0127 [MEDIUM] CVE-2021-0127: intel-microcode - Insufficient control flow management in some Intel(R) Processors may allow an au...
Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20220207.1)
bullseye: resolved (fixed in 3.20220207.1~deb11u1)
forky: resolved (fixed in 3.20220207.1)
sid: resolved (fixed in 3.20220207.1)
trixie: resolved (
debian
CVE-2019-11139P4MEDIUMCVSS 6.0fixed in intel-microcode 3.20191112.1 (bookworm)2019
CVE-2019-11139 [MEDIUM] CVE-2019-11139: intel-microcode - Improper conditions check in the voltage modulation interface for some Intel(R) ...
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 3.20191112.1)
bullseye: resolved (fixed in 3.20191112.1)
forky: resolved (fixed in 3.20191112.1)
sid: resolved (fixed in 3
debian
CVE-2023-23908P4MEDIUMCVSS 6.0fixed in intel-microcode 3.20230808.1~deb12u1 (bookworm)2023
CVE-2023-23908 [MEDIUM] CVE-2023-23908: intel-microcode - Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable process...
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20230808.1~deb12u1)
bullseye: resolved (fixed in 3.20230808.1~deb11u1)
forky: resolved (fixed in 3.20230808.1)
sid: resolved (fixed in 3.20
debian