CVE-2024-24968: Medium severity debian/intel-microcode vulnerability
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/intel-microcodeto a version that resolves this vulnerability.Fixed in 3.20240910.1~deb11u1Fixed in 3.20240910.1~deb12u1Fixed in 3.20241112.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24968?
CVE-2024-24968 has a severity rating that could allow a privileged user to potentially enable denial of service.
How do I fix CVE-2024-24968?
To fix CVE-2024-24968, you should update the affected intel-microcode packages to the specified fixed versions.
Which Intel processors are affected by CVE-2024-24968?
CVE-2024-24968 affects certain Intel processors that utilize improper finite state machines in their hardware logic.
Can two different versions of the intel-microcode package be simultaneously installed for CVE-2024-24968?
No, you must ensure that only one of the specified fixed versions of the intel-microcode package is installed to mitigate CVE-2024-24968.
Is local access required to exploit CVE-2024-24968?
Yes, exploitation of CVE-2024-24968 requires local access by a privileged user.