Uncaught Exception in Intel products - CVE-2025-20054

 

Uncaught Exception in Intel products - CVE-2025-20054

Published: May 19, 2025


Vulnerability identifier: #VU109427
CSH Severity: Low
CVSS v4 BT: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-20054
CWE-ID: CWE-248
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an uncaught exception in the core management mechanism for some Intel Processors. A local user can perform a denial of service (DoS) attack.


Affected software

Intel Xeon W Processors
4th Generation Intel Xeon Bronze Processors
4th Generation Intel Xeon Silver Processors
4th Generation Intel Xeon Gold Processors
4th Generation Intel Xeon Platinum processors
4th Generation Intel Xeon Scalable Processors
Intel Xeon CPU Max Series processors
14th Generation Intel Core Processors
13th Generation Intel Core Processors
Intel Xeon E Processors
12th Generation Intel Core Processors
5th Generation Intel Xeon Scalable processors
Intel Core Ultra family
Intel Celeron Processors
Intel Pentium Gold Processor Series
Alienware M18 R2
Vostro 15 3530
Vostro 14 3430
Inspiron 15 3530
Inspiron 16 Plus 7630
Inspiron 14 Plus 7430
XPS 8950
Alienware m16 R1
Alienware Aurora R13
Alienware m18 R1
PowerEdge R360
PowerEdge R260
PowerEdge T360
PowerEdge T160
PowerEdge XR5610
PowerEdge XR8610t
PowerEdge XR8620t
PowerEdge XR7620
PowerEdge XE9640
Dell XC Core XC660
Dell XC Core XC760
Dell XC Core XC660xs
Dell XC Core XC760xa
PowerEdge XE8640
PowerEdge R760xa
PowerEdge R660
PowerEdge R760
PowerEdge C6620
PowerEdge MX760c
PowerEdge R860
PowerEdge R960
PowerEdge HS5610
PowerEdge HS5620
PowerEdge R660xs
PowerEdge XE9680
PowerEdge R760xs
PowerEdge R760xd2
PowerEdge T560
Precision 7960 Tower
Precision 5860 Tower
HPE StoreEasy 1870 Storage
HPE StoreEasy 1870 Performance Storage
HPE StoreEasy 1670 Storage
HPE StoreEasy 1670 Performance Storage
Intel Core Ultra Processors Series 2
5th Generation Intel Xeon Bronze Processor
5th Generation Intel Xeon Silver Processor
5th Generation Intel Xeon Gold Processor
5th Generation Intel Xeon Platinum processor
Intel Core Ultra 200S Series Processor
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Fedora
microcode_ctl
intel-microcode (Ubuntu package)
intel-microcode (Debian package)
ucode-intel-debuginfo
ucode-intel
ucode-intel-debugsource
HPE StoreEasy 1570 Storage
HPE StoreEasy 1570 Performance
HPE StoreEasy 1470 Storage
HPE StoreEasy 1470 Performance

How to mitigate CVE-2025-20054

Install updates from vendor's website.

Alienware M18 R2 - update to 1.14.0
microcode_ctl - update to 1.17-102.83.84.1
Vostro 15 3530 - update to 1.20.0
Vostro 14 3430 - update to 1.20.0
Inspiron 15 3530 - update to 1.20.0
Inspiron 16 Plus 7630 - update to 1.21.0
Inspiron 14 Plus 7430 - update to 1.21.0
XPS 8950 - update to 1.26.0
Alienware m16 R1 - update to 1.26.0
Alienware Aurora R13 - update to 1.26.0
Alienware m18 R1 - update to 1.26.0
PowerEdge R360 - update to 2.1.1
PowerEdge R260 - update to 2.1.1
PowerEdge T360 - update to 2.1.1
PowerEdge T160 - update to 2.1.1
microcode_ctl - addressed in versions 2.1-67.2.fc41, 2.1-70.fc42
PowerEdge XR5610 - update to 2.6.3
PowerEdge XR8610t - update to 2.6.3
PowerEdge XR8620t - update to 2.6.3
PowerEdge XR7620 - update to 2.6.3
PowerEdge XE9640 - update to 2.6.3
Dell XC Core XC660 - update to 2.6.3
Dell XC Core XC760 - update to 2.6.3
Dell XC Core XC660xs - update to 2.6.3
Dell XC Core XC760xa - update to 2.6.3
PowerEdge XE8640 - update to 2.6.3
PowerEdge R760xa - update to 2.6.3
PowerEdge R660 - update to 2.6.3
PowerEdge R760 - update to 2.6.3
PowerEdge C6620 - update to 2.6.3
PowerEdge MX760c - update to 2.6.3
PowerEdge R860 - update to 2.6.3
PowerEdge R960 - update to 2.6.3
PowerEdge HS5610 - update to 2.6.3
PowerEdge HS5620 - update to 2.6.3
PowerEdge R660xs - update to 2.6.3
PowerEdge XE9680 - update to 2.6.3
PowerEdge R760xs - update to 2.6.3
PowerEdge R760xd2 - update to 2.6.3
PowerEdge T560 - update to 2.6.3
Precision 7960 Tower - update to 2.10.0
Precision 5860 Tower - update to 2.10.0
HPE StoreEasy 1870 Storage - update to 2.50_04-22-2025
HPE StoreEasy 1870 Performance Storage - update to 2.50_04-22-2025
HPE StoreEasy 1670 Storage - update to 2.50_04-22-2025
HPE StoreEasy 1670 Performance Storage - update to 2.50_04-22-2025
HPE StoreEasy 1570 Storage - update to 2.50_04-22-2025
HPE StoreEasy 1570 Performance - update to 2.50_04-22-2025
HPE StoreEasy 1470 Storage - update to 2.50_04-22-2025
HPE StoreEasy 1470 Performance - update to 2.50_04-22-2025
intel-microcode (Ubuntu package) - addressed in versions 3.20250512.0ubuntu0.16.04.1+esm1, 3.20250512.0ubuntu0.18.04.1+esm1, 3.20250512.0ubuntu0.20.04.1, 3.20250512.0ubuntu0.22.04.1, 3.20250512.0ubuntu0.24.04.1, 3.20250512.0ubuntu0.24.10.1, 3.20250512.0ubuntu0.25.04.1
intel-microcode (Debian package) - update to 3.20250512.1~deb12u1
microcode_ctl - update to 20250512-1
ucode-intel-debuginfo - update to 20250512-152.1
ucode-intel - addressed in versions 20250512-152.1, 20250512-150200.56.1
ucode-intel-debugsource - update to 20250512-152.1

External References

Related Security Bulletins