Missing initialization of resource in Intel products - CVE-2025-24495
Published: May 14, 2025
Vulnerability identifier: #VU109169
CSH Severity: Low
CVSS v4 BT: 1.9 [CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-24495
CWE-ID: CWE-909
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to incorrect initialization of resource in the branch prediction unit. A local user can gain unauthorized access to sensitive information on the system.
Affected software
Intel Core Ultra 5
Intel Core Ultra 7
Intel Core Ultra 9
XPS 13 9350
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Qradar SIEM
microcode_ctl
intel-microcode (Ubuntu package)
intel-microcode (Debian package)
microcode_ctl (Red Hat package)
ucode-intel-debuginfo
ucode-intel
ucode-intel-debugsource
Intel Core Ultra 7
Intel Core Ultra 9
XPS 13 9350
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Qradar SIEM
microcode_ctl
intel-microcode (Ubuntu package)
intel-microcode (Debian package)
microcode_ctl (Red Hat package)
ucode-intel-debuginfo
ucode-intel
ucode-intel-debugsource
How to mitigate CVE-2025-24495
Install updates from vendor's website.
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
XPS 13 9350 - update to 1.11.2
microcode_ctl - update to 1.17-102.83.84.1
microcode_ctl - addressed in versions 2.1-67.2.fc41, 2.1-70.fc42
intel-microcode (Ubuntu package) - addressed in versions 3.20250512.0ubuntu0.16.04.1+esm1, 3.20250512.0ubuntu0.18.04.1+esm1, 3.20250512.0ubuntu0.20.04.1, 3.20250512.0ubuntu0.22.04.1, 3.20250512.0ubuntu0.24.04.1, 3.20250512.0ubuntu0.24.10.1, 3.20250512.0ubuntu0.25.04.1
intel-microcode (Debian package) - update to 3.20250512.1~deb12u1
microcode_ctl (Red Hat package) - addressed in versions 20220207-1.20250512.1.el9_0, 20220809-2.20250512.1.el9_2, 20230808-2.20250512.1.el9_4
microcode_ctl - update to 20250512-1
microcode_ctl - update to 20250512-1.0.1
ucode-intel-debuginfo - update to 20250512-152.1
ucode-intel - addressed in versions 20250512-152.1, 20250512-150200.56.1
ucode-intel-debugsource - update to 20250512-152.1
XPS 13 9350 - update to 1.11.2
microcode_ctl - update to 1.17-102.83.84.1
microcode_ctl - addressed in versions 2.1-67.2.fc41, 2.1-70.fc42
intel-microcode (Ubuntu package) - addressed in versions 3.20250512.0ubuntu0.16.04.1+esm1, 3.20250512.0ubuntu0.18.04.1+esm1, 3.20250512.0ubuntu0.20.04.1, 3.20250512.0ubuntu0.22.04.1, 3.20250512.0ubuntu0.24.04.1, 3.20250512.0ubuntu0.24.10.1, 3.20250512.0ubuntu0.25.04.1
intel-microcode (Debian package) - update to 3.20250512.1~deb12u1
microcode_ctl (Red Hat package) - addressed in versions 20220207-1.20250512.1.el9_0, 20220809-2.20250512.1.el9_2, 20230808-2.20250512.1.el9_4
microcode_ctl - update to 20250512-1
microcode_ctl - update to 20250512-1.0.1
ucode-intel-debuginfo - update to 20250512-152.1
ucode-intel - addressed in versions 20250512-152.1, 20250512-150200.56.1
ucode-intel-debugsource - update to 20250512-152.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel Core Ultra Processors
- openEuler update for microcode_ctl
- SUSE update for microcode_ctl
- Dell Client Platform update for Intel Core Ultra Processor firmware
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- Debian update for intel-microcode
- Fedora 41 update for microcode_ctl
- Fedora 42 update for microcode_ctl
- Ubuntu update for intel-microcode
- SUSE update for ucode-intel
- Red Hat Enterprise Linux 9 update for microcode_ctl
- Red Hat Enterprise Linux 9 update for microcode_ctl
- Red Hat Enterprise Linux 9 update for microcode_ctl
- Anolis OS update for microcode_ctl
- Multiple vulnerabilities in IBM QRadar SIEM