Sequence of processor instructions leads to unexpected behavior in Intel products - CVE-2024-37020

 

Sequence of processor instructions leads to unexpected behavior in Intel products - CVE-2024-37020

Published: February 17, 2025


Vulnerability identifier: #VU104007
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37020
CWE-ID: CWE-1281
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an error related to processing of Sequence of processor instructions. A local user can cause a denial of service condition on the target system.


Affected software

Intel Driver and Support Assistant (DSA)
4th Generation Intel Xeon Scalable Processors
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Bronze Processors
4th Generation Intel Xeon Scalable Processors with Intel vRAN
Intel Xeon W workstation processors
5th Generation Intel Xeon Scalable processors
Intel Atom P6900 Processor
Intel Xeon 6 processor with E-cores
PowerEdge R760xs
PowerEdge R660
PowerEdge R760
PowerEdge C6620
PowerEdge MX760c
PowerEdge R860
PowerEdge R960
PowerEdge HS5610
PowerEdge HS5620
PowerEdge R660xs
PowerEdge R760xd2
PowerEdge T560
PowerEdge XR8620t
Dell XC Core XC760xa
Dell XC Core XC660xs
Dell XC Core XC760
Dell XC Core XC660
PowerEdge XE9640
PowerEdge XE8640
PowerEdge XR7620
PowerEdge R760xa
PowerEdge XR8610t
PowerEdge XR5610
PowerEdge XE9680
HPE StoreEasy 1870 Storage
HPE StoreEasy 1870 Performance Storage
HPE StoreEasy 1670 Storage
HPE StoreEasy 1670 Performance Storage
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Basesystem Module
openSUSE Leap
openEuler
Fedora
APEX Cloud Platform for Microsoft Azure
HPE StoreEasy 1570 Storage
HPE StoreEasy 1570 Performance
HPE StoreEasy 1470 Storage
HPE StoreEasy 1470 Performance
microcode_ctl
ucode-intel-debuginfo
ucode-intel
ucode-intel-debugsource
APEX Cloud Platform for Red Hat OpenShift
PowerProtect Data Manager
Dell Integrated System for Microsoft Azure Stack Hub 16G

How to mitigate CVE-2024-37020

Install updates from vendor's website.

APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
microcode_ctl - addressed in versions 2.1-61.6.fc40, 2.1-67.1.fc41
HPE StoreEasy 1870 Storage - update to 2.44_01-17-2025
HPE StoreEasy 1870 Performance Storage - update to 2.44_01-17-2025
HPE StoreEasy 1670 Storage - update to 2.44_01-17-2025
HPE StoreEasy 1670 Performance Storage - update to 2.44_01-17-2025
HPE StoreEasy 1570 Storage - update to 2.44_01-17-2025
HPE StoreEasy 1570 Performance - update to 2.44_01-17-2025
HPE StoreEasy 1470 Storage - update to 2.44_01-17-2025
HPE StoreEasy 1470 Performance - update to 2.44_01-17-2025
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
PowerProtect Data Manager - update to 19.19.0-15
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502
microcode_ctl - update to 20250211-1
ucode-intel-debuginfo - update to 20250211-149.2
ucode-intel - addressed in versions 20250211-149.2, 20250211-150200.53.1
ucode-intel-debugsource - update to 20250211-149.2

External References

Related Security Bulletins