CVE-2024-23984: Medium severity debian/intel-microcode vulnerability
Published Sep 16, 2024
·Updated
Last updated 8 December 2024
Other sources
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
— NVD
Affected Software
1 affected componentFixes available
debian/intel-microcode<=3.20240813.1~deb11u1, <=3.20231114.1~deb12u1
3.20240910.1~deb11u13.20240910.1~deb12u13.20241112.1
Event History
Sep 11, 2024
News Published
via The Register·01:27 AM
Sep 15, 2024
News Published
via The Register·01:30 AM
Sep 16, 2024
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Dec 11, 2024
Data Sourced
via Ubuntu·03:11 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23984?
CVE-2024-23984 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-23984?
To fix CVE-2024-23984, update the intel-microcode package to version 3.20240910.1~deb11u1 or later.
3
What is CVE-2024-23984 about?
CVE-2024-23984 relates to an observable discrepancy in the RAPL interface for certain Intel processors that may allow a privileged user to disclose information locally.
4
Who is affected by CVE-2024-23984?
CVE-2024-23984 affects users of specific Intel processors running vulnerable versions of the intel-microcode package.
5
Is CVE-2024-23984 exploitable remotely?
CVE-2024-23984 requires local access for exploitation, thus it is not remotely exploitable.