Resource management error in 3rd Generation Intel Xeon Scalable Processors - CVE-2024-25939

 

Resource management error in 3rd Generation Intel Xeon Scalable Processors - CVE-2024-25939

Published: August 19, 2024


Vulnerability identifier: #VU96213
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25939
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. Mirrored regions with different values in 3rd Generation Intel Xeon Scalable Processors may allow a local privileged user to crash the system.


Affected software

3rd Generation Intel Xeon Scalable Processors
Superdome Flex 280 Server
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
Fedora
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
CloudBoost Virtual Appliance

How to mitigate CVE-2024-25939

Install updates from vendor's website.

RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
Superdome Flex 280 Server - update to 1.90.12
microcode_ctl - addressed in versions 2.1-58.2.fc39, 2.1-61.2.fc40, 2.1-64.fc41
CloudBoost Virtual Appliance - update to 19.12.0.1
microcode_ctl - update to 20240813-1
ucode-intel - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel-debugsource - update to 20240813-140.1

External References

Related Security Bulletins