Resource management error in 3rd Generation Intel Xeon Scalable Processors - CVE-2024-25939
Published: August 19, 2024
Vulnerability identifier: #VU96213
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25939
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application. Mirrored regions with different values in 3rd Generation Intel Xeon
Scalable Processors may allow a local privileged user to crash the system.
Affected software
3rd Generation Intel Xeon Scalable Processors
Superdome Flex 280 Server
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
Fedora
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
CloudBoost Virtual Appliance
Superdome Flex 280 Server
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Ubuntu
openEuler
Fedora
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
CloudBoost Virtual Appliance
How to mitigate CVE-2024-25939
Install updates from vendor's website.
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
Superdome Flex 280 Server - update to 1.90.12
microcode_ctl - addressed in versions 2.1-58.2.fc39, 2.1-61.2.fc40, 2.1-64.fc41
CloudBoost Virtual Appliance - update to 19.12.0.1
microcode_ctl - update to 20240813-1
ucode-intel - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel-debugsource - update to 20240813-140.1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240813.0ubuntu0.20.04.2, 3.20240813.0ubuntu0.22.04.2, 3.20240813.0ubuntu0.24.04.2
Superdome Flex 280 Server - update to 1.90.12
microcode_ctl - addressed in versions 2.1-58.2.fc39, 2.1-61.2.fc40, 2.1-64.fc41
CloudBoost Virtual Appliance - update to 19.12.0.1
microcode_ctl - update to 20240813-1
ucode-intel - update to 20240813-140.1
ucode-intel-debuginfo - update to 20240813-140.1
ucode-intel-debugsource - update to 20240813-140.1
External References
Related Security Bulletins
- Denial of service in 3rd Generation Intel Xeon Scalable processors
- Ubuntu update for intel-microcode
- SUSE update for ucode-intel
- Fedora 39 update for microcode_ctl
- Fedora 41 update for microcode_ctl
- Fedora 40 update for microcode_ctl
- openEuler update for microcode_ctl
- HPE Superdome Flex 280 servers update for Intel 3rd Gen Xeon firmware
- Dell RecoverPoint for Virtual Machines update for third-party components
- Dell CloudBoost Virtual Appliance update for third-party components