CVE-2020-24513: Infoleak
A potential domain bypass transient execution vulnerability was discovered on some Intel Atom® processors that uses a microarchitectural incidental channel. Currently this channel can reveal supervisor data in the L1 cache and the contents of recent stores. As a consequence, this issue may allow an authenticated user to potentially enable information disclosure via local access.
Other sources
Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this Intel Atom processor vulnerability?
The vulnerability ID for this Intel Atom processor vulnerability is CVE-2020-24513.
What is the severity level of CVE-2020-24513?
CVE-2020-24513 has a severity level of medium.
How does CVE-2020-24513 affect Intel Atom processors?
CVE-2020-24513 can reveal supervisor data in the L1 cache and the contents of recent stores on some Intel Atom processors.
Which software versions are affected by CVE-2020-24513?
The affected software versions include debian/intel-microcode:3.20220510.1~deb10u1, debian/intel-microcode:3.20230808.1~deb10u1, debian/intel-microcode:3.20230808.1~deb11u1, debian/intel-microcode:3.20230808.1~deb12u1, and debian/intel-microcode:3.20230808.1.
How can I fix CVE-2020-24513?
To fix CVE-2020-24513, update the intel-microcode package to the recommended versions provided by the vendor.