|
|
Log in / Subscribe / Register

Debian alert DLA-3964-1 (intel-microcode)

From:  Tobias Frost <tobi@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 3964-1] intel-microcode security update
Date:  Sun, 24 Nov 2024 15:40:09 +0100
Message-ID:  <Z0M6yQZc729tb0NG@isildor2.loewenhoehle.ip>

------------------------------------------------------------------------- Debian LTS Advisory DLA-3964-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Tobias Frost November 24, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : intel-microcode Version : 3.20240910.1~deb11u1 CVE ID : CVE-2024-23984 CVE-2024-24968 Debian Bug : 1081363 A microcode update has been released for Intel processors, addressing multiple vulnerabilties which potentially could cause information disclosue or local DoS. CVE-2024-23984 Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. CVE-2024-24968 Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access. For Debian 11 bullseye, these problems have been fixed in version 3.20240910.1~deb11u1. We recommend that you upgrade your intel-microcode packages. For the detailed security status of intel-microcode please refer to its security tracker page at: https://security-tracker.debian.org/tracker/intel-microcode Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEE/d0M/zhkJ3YwohhskWT6HRe9XTYFAmdDOsYACgkQkWT6HRe9 XTZ3xhAAhrO4+Xm/33i3Wl3sk4FDc64H6VKNsJhuiYOSNgtrUfoz+fs8NIXwbR76 wiTlyd7lDmJZ67+MtfOooiud3uffcd4wzcB1cbrmk1pBfhxxRkAhwD4bthA9G5il HXtDULtp7UbhmxsFF8ONecyBQfpOb2CgNPgqgmgocZgV12X2kb6rTjJv6klp//Pb nZ48pbtwHDB1en/JHRIv/mgOQ3rEZk29glP0OlDwrhKPiMYKu0iOew53B70AAL4m ojmyxg/Lgwj2UL7ecsO/TcGs4gpbWMuR0feJ1+57dehDDJtd8QhaUqJyvnjwYoTN BXRlfi2BtCHst1uDiWBdPsIKEvaHazpp9mTBBfKjtiCjp40qSA+f/jql98GhKvZi +DfDuwDNlIbeJDRQrqaf/g0rw07oHb/dP/Coamfu4xPFCDusf+7DIeZoNcy6Qr3q iX37oMc6z0NbEAvxKbXsUx91glDw0cCEMxPVBLX84IRMy4IclcU9YCR1gffUGahR SLOWhltU8T27Mi+/vYlDvi8U5lqR7865NAgYp+n61pSnVRm/5NY5IBGSvawNPbcS qcqpgq36YByWk7ty/G+O6/9Ms9D6c4DrNGlrL6N8CAtyybQ5f7m3zb8x9i3l0Abm TyQ/keLDBrs5eOII3sp4oGDXYJwU1/A7hdI139rU5EeDoqehG4Q= =P9Jm -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds