Input validation error in Intel products - CVE-2024-39279

 

Input validation error in Intel products - CVE-2024-39279

Published: February 18, 2025


Vulnerability identifier: #VU104039
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39279
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient granularity of access control. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

UEFI firmware
Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
Intel 4th Generation Intel Xeon Scalable Processors
Intel Atom Processor C5000
Intel Atom Processor P5000 Series
PowerEdge XR8610t
PowerEdge HS5610
PowerEdge HS5620
PowerEdge R660xs
PowerEdge R760xs
PowerEdge R760xd2
PowerEdge T560
PowerEdge R760xa
PowerEdge XE9680
PowerEdge XR5610
PowerEdge R960
PowerEdge XR8620t
PowerEdge XR7620
PowerEdge XE8640
PowerEdge XE9640
Dell XC Core XC660
Dell XC Core XC760
Dell XC Core XC660xs
Dell XC Core XC760xa
PowerEdge R860
PowerEdge MX760c
PowerEdge C6620
PowerEdge R760
PowerEdge R660
PowerEdge R350
PowerEdge T150
PowerEdge T350
PowerEdge R250
Dell EMC XC Core XC650
Dell EMC XC Core XC450
PowerEdge R650XS
Dell EMC XC Core XC750
Dell EMC XC Core XC750xa
Dell EMC XC Core XC6520
PowerEdge XR12
PowerEdge XR11
PowerEdge T550
PowerEdge R750XS
PowerEdge R450
PowerEdge R550
PowerEdge MX750c
PowerEdge C6520
PowerEdge R750XA
PowerEdge R750
PowerEdge R650
PowerEdge XR4510c
PowerEdge XR4520c
Precision 7960 Tower
Precision 5860 Tower
Ubuntu
openEuler
Fedora
intel-microcode (Ubuntu package)
microcode_ctl
APEX Cloud Platform for Microsoft Azure
APEX Cloud Platform for Red Hat OpenShift
Dell Integrated System for Microsoft Azure Stack Hub 16G

How to mitigate CVE-2024-39279

Install updates from vendor's website.

intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20250211.0ubuntu0.20.04.1, 3.20250211.0ubuntu0.22.04.1, 3.20250211.0ubuntu0.24.04.1, 3.20250211.0ubuntu0.24.10.1
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
PowerEdge R350 - update to 1.11.1
PowerEdge T150 - update to 1.11.1
PowerEdge T350 - update to 1.11.1
PowerEdge R250 - update to 1.11.1
Dell EMC XC Core XC650 - update to 1.16.2
Dell EMC XC Core XC450 - update to 1.16.2
PowerEdge R650XS - update to 1.16.2
Dell EMC XC Core XC750 - update to 1.16.2
Dell EMC XC Core XC750xa - update to 1.16.2
Dell EMC XC Core XC6520 - update to 1.16.2
PowerEdge XR12 - update to 1.16.2
PowerEdge XR11 - update to 1.16.2
PowerEdge T550 - update to 1.16.2
PowerEdge R750XS - update to 1.16.2
PowerEdge R450 - update to 1.16.2
PowerEdge R550 - update to 1.16.2
PowerEdge MX750c - update to 1.16.2
PowerEdge C6520 - update to 1.16.2
PowerEdge R750XA - update to 1.16.2
PowerEdge R750 - update to 1.16.2
PowerEdge R650 - update to 1.16.2
PowerEdge XR4510c - update to 1.17.3
PowerEdge XR4520c - update to 1.17.3
microcode_ctl - addressed in versions 2.1-61.6.fc40, 2.1-67.1.fc41
Precision 7960 Tower - update to 2.6.1
Precision 5860 Tower - update to 2.6.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502
microcode_ctl - update to 20250211-1

External References

Related Security Bulletins