Input validation error in Intel products - CVE-2024-39279
Published: February 18, 2025
Vulnerability identifier: #VU104039
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39279
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient granularity of access control. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
UEFI firmware
Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
Intel 4th Generation Intel Xeon Scalable Processors
Intel Atom Processor C5000
Intel Atom Processor P5000 Series
PowerEdge XR8610t
PowerEdge HS5610
PowerEdge HS5620
PowerEdge R660xs
PowerEdge R760xs
PowerEdge R760xd2
PowerEdge T560
PowerEdge R760xa
PowerEdge XE9680
PowerEdge XR5610
PowerEdge R960
PowerEdge XR8620t
PowerEdge XR7620
PowerEdge XE8640
PowerEdge XE9640
Dell XC Core XC660
Dell XC Core XC760
Dell XC Core XC660xs
Dell XC Core XC760xa
PowerEdge R860
PowerEdge MX760c
PowerEdge C6620
PowerEdge R760
PowerEdge R660
PowerEdge R350
PowerEdge T150
PowerEdge T350
PowerEdge R250
Dell EMC XC Core XC650
Dell EMC XC Core XC450
PowerEdge R650XS
Dell EMC XC Core XC750
Dell EMC XC Core XC750xa
Dell EMC XC Core XC6520
PowerEdge XR12
PowerEdge XR11
PowerEdge T550
PowerEdge R750XS
PowerEdge R450
PowerEdge R550
PowerEdge MX750c
PowerEdge C6520
PowerEdge R750XA
PowerEdge R750
PowerEdge R650
PowerEdge XR4510c
PowerEdge XR4520c
Precision 7960 Tower
Precision 5860 Tower
Ubuntu
openEuler
Fedora
intel-microcode (Ubuntu package)
microcode_ctl
APEX Cloud Platform for Microsoft Azure
APEX Cloud Platform for Red Hat OpenShift
Dell Integrated System for Microsoft Azure Stack Hub 16G
Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
Intel 4th Generation Intel Xeon Scalable Processors
Intel Atom Processor C5000
Intel Atom Processor P5000 Series
PowerEdge XR8610t
PowerEdge HS5610
PowerEdge HS5620
PowerEdge R660xs
PowerEdge R760xs
PowerEdge R760xd2
PowerEdge T560
PowerEdge R760xa
PowerEdge XE9680
PowerEdge XR5610
PowerEdge R960
PowerEdge XR8620t
PowerEdge XR7620
PowerEdge XE8640
PowerEdge XE9640
Dell XC Core XC660
Dell XC Core XC760
Dell XC Core XC660xs
Dell XC Core XC760xa
PowerEdge R860
PowerEdge MX760c
PowerEdge C6620
PowerEdge R760
PowerEdge R660
PowerEdge R350
PowerEdge T150
PowerEdge T350
PowerEdge R250
Dell EMC XC Core XC650
Dell EMC XC Core XC450
PowerEdge R650XS
Dell EMC XC Core XC750
Dell EMC XC Core XC750xa
Dell EMC XC Core XC6520
PowerEdge XR12
PowerEdge XR11
PowerEdge T550
PowerEdge R750XS
PowerEdge R450
PowerEdge R550
PowerEdge MX750c
PowerEdge C6520
PowerEdge R750XA
PowerEdge R750
PowerEdge R650
PowerEdge XR4510c
PowerEdge XR4520c
Precision 7960 Tower
Precision 5860 Tower
Ubuntu
openEuler
Fedora
intel-microcode (Ubuntu package)
microcode_ctl
APEX Cloud Platform for Microsoft Azure
APEX Cloud Platform for Red Hat OpenShift
Dell Integrated System for Microsoft Azure Stack Hub 16G
How to mitigate CVE-2024-39279
Install updates from vendor's website.
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20250211.0ubuntu0.20.04.1, 3.20250211.0ubuntu0.22.04.1, 3.20250211.0ubuntu0.24.04.1, 3.20250211.0ubuntu0.24.10.1
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
PowerEdge R350 - update to 1.11.1
PowerEdge T150 - update to 1.11.1
PowerEdge T350 - update to 1.11.1
PowerEdge R250 - update to 1.11.1
Dell EMC XC Core XC650 - update to 1.16.2
Dell EMC XC Core XC450 - update to 1.16.2
PowerEdge R650XS - update to 1.16.2
Dell EMC XC Core XC750 - update to 1.16.2
Dell EMC XC Core XC750xa - update to 1.16.2
Dell EMC XC Core XC6520 - update to 1.16.2
PowerEdge XR12 - update to 1.16.2
PowerEdge XR11 - update to 1.16.2
PowerEdge T550 - update to 1.16.2
PowerEdge R750XS - update to 1.16.2
PowerEdge R450 - update to 1.16.2
PowerEdge R550 - update to 1.16.2
PowerEdge MX750c - update to 1.16.2
PowerEdge C6520 - update to 1.16.2
PowerEdge R750XA - update to 1.16.2
PowerEdge R750 - update to 1.16.2
PowerEdge R650 - update to 1.16.2
PowerEdge XR4510c - update to 1.17.3
PowerEdge XR4520c - update to 1.17.3
microcode_ctl - addressed in versions 2.1-61.6.fc40, 2.1-67.1.fc41
Precision 7960 Tower - update to 2.6.1
Precision 5860 Tower - update to 2.6.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502
microcode_ctl - update to 20250211-1
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
PowerEdge R350 - update to 1.11.1
PowerEdge T150 - update to 1.11.1
PowerEdge T350 - update to 1.11.1
PowerEdge R250 - update to 1.11.1
Dell EMC XC Core XC650 - update to 1.16.2
Dell EMC XC Core XC450 - update to 1.16.2
PowerEdge R650XS - update to 1.16.2
Dell EMC XC Core XC750 - update to 1.16.2
Dell EMC XC Core XC750xa - update to 1.16.2
Dell EMC XC Core XC6520 - update to 1.16.2
PowerEdge XR12 - update to 1.16.2
PowerEdge XR11 - update to 1.16.2
PowerEdge T550 - update to 1.16.2
PowerEdge R750XS - update to 1.16.2
PowerEdge R450 - update to 1.16.2
PowerEdge R550 - update to 1.16.2
PowerEdge MX750c - update to 1.16.2
PowerEdge C6520 - update to 1.16.2
PowerEdge R750XA - update to 1.16.2
PowerEdge R750 - update to 1.16.2
PowerEdge R650 - update to 1.16.2
PowerEdge XR4510c - update to 1.17.3
PowerEdge XR4520c - update to 1.17.3
microcode_ctl - addressed in versions 2.1-61.6.fc40, 2.1-67.1.fc41
Precision 7960 Tower - update to 2.6.1
Precision 5860 Tower - update to 2.6.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Dell Integrated System for Microsoft Azure Stack Hub 16G - update to 2502
microcode_ctl - update to 20250211-1
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel UEFI Firmware
- Ubuntu update for intel-microcode
- Ubuntu update for intel-microcode
- Fedora 40 update for microcode_ctl
- Fedora 41 update for microcode_ctl
- openEuler update for microcode_ctl
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell Client Platform
- Multiple vulnerabilities in Dell PowerEdge Server
- Multiple vulnerabilities in Dell Integrated System
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components