State Issues in Intel products - CVE-2024-24968
Published: September 17, 2024
Vulnerability identifier: #VU97423
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-24968
CWE-ID: CWE-371
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service attack.
The vulnerability exists due to improper finite state machines (FSMs) in hardware logic. A local privileged user can perform a denial of service (DoS) attack.
Affected software
11th Generation Intel Core Processors
12th Generation Intel Core Processors
13th Generation Intel Core Processors
Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
10th Generation Intel Core Processors
Intel Processor Microcode Package for Linux
HPE StoreEasy 1860 Storage
HPE StoreEasy 1660 Storage
Precision 7920 Rack
Precision 7920 XL Rack
HPE SimpliVity 380 Gen11
HPE SimpliVity 380 Gen10 Plus
13th Generation Intel Core i7 processors
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
APEX Cloud Platform for Microsoft Azure
StoreEasy 1870 Expanded Storage
StoreEasy 1860 Expanded Storage
StoreEasy 1670 Expanded Storage
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
APEX Cloud Platform for Red Hat OpenShift
Apstra
Red Hat OpenShift Container Platform
12th Generation Intel Core Processors
13th Generation Intel Core Processors
Intel Xeon D Processors
3rd Generation Intel Xeon Scalable Processors
10th Generation Intel Core Processors
Intel Processor Microcode Package for Linux
HPE StoreEasy 1860 Storage
HPE StoreEasy 1660 Storage
Precision 7920 Rack
Precision 7920 XL Rack
HPE SimpliVity 380 Gen11
HPE SimpliVity 380 Gen10 Plus
13th Generation Intel Core i7 processors
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
APEX Cloud Platform for Microsoft Azure
StoreEasy 1870 Expanded Storage
StoreEasy 1860 Expanded Storage
StoreEasy 1670 Expanded Storage
RecoverPoint for Virtual Machines
intel-microcode (Ubuntu package)
microcode_ctl
ucode-intel
ucode-intel-debuginfo
ucode-intel-debugsource
APEX Cloud Platform for Red Hat OpenShift
Apstra
Red Hat OpenShift Container Platform
How to mitigate CVE-2024-24968
Install updates from vendor's website.
Intel Processor Microcode Package for Linux - update to 20240910
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240910.0ubuntu0.20.04.1, 3.20240910.0ubuntu0.22.04.1, 3.20240910.0ubuntu0.24.04.1, 3.20241112.0ubuntu0.20.04.1, 3.20241112.0ubuntu0.22.04.1, 3.20241112.0ubuntu0.24.04.1, 3.20241112.0ubuntu0.24.10.1
microcode_ctl - update to 2.1-47.44
microcode_ctl - addressed in versions 2.1-58.3.fc39, 2.1-61.3.fc40, 2.1-65.fc41
StoreEasy 1870 Expanded Storage - update to 2.20_08-07-2024
HPE StoreEasy 1860 Storage - update to 2.20_08-07-2024
StoreEasy 1860 Expanded Storage - update to 2.20_08-07-2024
HPE StoreEasy 1660 Storage - update to 2.20_08-07-2024
StoreEasy 1670 Expanded Storage - update to 2.20_08-07-2024
Precision 7920 Rack - update to 2.22.2
Precision 7920 XL Rack - update to 2.22.2
APEX Cloud Platform for Red Hat OpenShift - update to 03.03.00.00
Red Hat OpenShift Container Platform - update to 4.16.25
Apstra - update to 6.0.0
HPE SimpliVity 380 Gen11 - update to 2024_1129
HPE SimpliVity 380 Gen10 Plus - update to 2024_1129
microcode_ctl - update to 20240910-1
ucode-intel - addressed in versions 20240910-143.1, 20240910-150200.47.1, 20241112-146.1, 20241112-150200.50.1
ucode-intel-debuginfo - addressed in versions 20240910-143.1, 20241112-146.1
ucode-intel-debugsource - addressed in versions 20240910-143.1, 20241112-146.1
microcode_ctl - update to 20250211-1
APEX Cloud Platform for Microsoft Azure - update to 01.04.00.00
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
intel-microcode (Ubuntu package) - addressed in versions Ubuntu Pro, 3.20240910.0ubuntu0.20.04.1, 3.20240910.0ubuntu0.22.04.1, 3.20240910.0ubuntu0.24.04.1, 3.20241112.0ubuntu0.20.04.1, 3.20241112.0ubuntu0.22.04.1, 3.20241112.0ubuntu0.24.04.1, 3.20241112.0ubuntu0.24.10.1
microcode_ctl - update to 2.1-47.44
microcode_ctl - addressed in versions 2.1-58.3.fc39, 2.1-61.3.fc40, 2.1-65.fc41
StoreEasy 1870 Expanded Storage - update to 2.20_08-07-2024
HPE StoreEasy 1860 Storage - update to 2.20_08-07-2024
StoreEasy 1860 Expanded Storage - update to 2.20_08-07-2024
HPE StoreEasy 1660 Storage - update to 2.20_08-07-2024
StoreEasy 1670 Expanded Storage - update to 2.20_08-07-2024
Precision 7920 Rack - update to 2.22.2
Precision 7920 XL Rack - update to 2.22.2
APEX Cloud Platform for Red Hat OpenShift - update to 03.03.00.00
Red Hat OpenShift Container Platform - update to 4.16.25
Apstra - update to 6.0.0
HPE SimpliVity 380 Gen11 - update to 2024_1129
HPE SimpliVity 380 Gen10 Plus - update to 2024_1129
microcode_ctl - update to 20240910-1
ucode-intel - addressed in versions 20240910-143.1, 20240910-150200.47.1, 20241112-146.1, 20241112-150200.50.1
ucode-intel-debuginfo - addressed in versions 20240910-143.1, 20241112-146.1
ucode-intel-debugsource - addressed in versions 20240910-143.1, 20241112-146.1
microcode_ctl - update to 20250211-1
External References
Related Security Bulletins
- Local denial of service in Intel processors FSMs
- Fedora 40 update for microcode_ctl
- Fedora 41 update for microcode_ctl
- Fedora 39 update for microcode_ctl
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- openEuler update for microcode_ctl
- Ubuntu update for intel-microcode
- Dell Precision Rack update for Intel CPU firmware
- Amazon Linux AMI update for microcode_ctl
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- HPE SimpliVity servers update for Intel firmware
- SUSE update for ucode-intel
- SUSE update for ucode-intel
- Ubuntu update for intel-microcode
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- State issues in HPE StoreEasy Servers Using Certain Intel Processors
- APEX Cloud Platform for Microsoft Azure update for third-party components
- Dell RecoverPoint for Virtual Machines update for third-party components
- Anolis OS update for microcode_ctl
- Juniper Apstra update for Intel-microcode package