ELA-1425-1 intel-microcode security update

microcode update

2025-05-18
Packageintel-microcode
Version3.20250512.1~deb8u1 (jessie), 3.20250512.1~deb9u1 (stretch), 3.20250512.1~deb10u1 (buster)
Related CVEs CVE-2024-28956 CVE-2024-43420 CVE-2024-45332 CVE-2025-20012 CVE-2025-20054 CVE-2025-20103 CVE-2025-20623 CVE-2025-24495


Microcode updates have been released for Intel(R) processors, addressing multiple potential vulnerabilties that may allow denial of service or information disclosure.

CVE-2024-28956

Exposure of Sensitive Information in Shared Microarchitectural
Structures during Transient Execution for some Intel(R) Processors
may allow an authenticated user to potentially enable information
disclosure via local access.

CVE-2024-43420

Exposure of sensitive information caused by shared
microarchitectural predictor state that influences transient
execution for some Intel Atom(R) processors may allow an
authenticated user to potentially enable information disclosure via
local access.

CVE-2024-45332

Exposure of sensitive information caused by shared
microarchitectural predictor state that influences transient
execution in the indirect branch predictors for some Intel(R)
Processors may allow an authenticated user to potentially enable
information disclosure via local access.

CVE-2025-20012

Incorrect behavior order for some Intel(R) Core™ Ultra Processors
may allow an unauthenticated user to potentially enable information
disclosure via physical access.

CVE-2025-20054

Uncaught exception in the core management mechanism for some
Intel(R) Processors may allow an authenticated user to potentially
enable denial of service via local access.

CVE-2025-20103

Insufficient resource pool in the core management mechanism for some
Intel(R) Processors may allow an authenticated user to potentially
enable denial of service via local access.

CVE-2025-20623

Exposure of sensitive information caused by shared
microarchitectural predictor state that influences transient
execution for some Intel(R) Core™ processors (10th Generation) may
allow an authenticated user to potentially enable information
disclosure via local access.

CVE-2025-24495

Incorrect initialization of resource in the branch prediction unit
for some Intel(R) Core™ Ultra Processors may allow an authenticated
user to potentially enable information disclosure via local access.


For Debian 10 buster, these problems have been fixed in version 3.20250512.1~deb10u1.

For Debian 8 jessie, these problems have been fixed in version 3.20250512.1~deb8u1.

For Debian 9 stretch, these problems have been fixed in version 3.20250512.1~deb9u1.

We recommend that you upgrade your intel-microcode packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.