USN-6967-1: Intel Microcode vulnerabilities
It was discovered that some Intel® Core™ Ultra Processors did not properly isolate the stream cache. A local authenticated user could potentially use this to escalate their privileges. (CVE-2023-42667) It was discovered that some Intel® Processors did not properly isolate the stream cache. A local authenticated user could potentially use this to escalate their privileges. (CVE-2023-49141) It was discovered that some Intel® Processors did not correctly transition between the executive monitor and SMI transfer monitor (STM). A privileged local attacker could use this to escalate their privileges. (CVE-2024-24853) It was discovered that some 3rd, 4th, and 5th Generation Intel® Xeon® Processors failed to properly implement a protection mechanism. A local attacker could use this to potentially escalate their privileges. (CVE-2024-24980) It was discovered that some 3rd Generation Intel Xeon Scalable Processors did not properly handle mirrored regions with different values. A privileged local user could use this to cause a denial of service (system crash). (CVE-2024-25939)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6967-1?
USN-6967-1 has been categorized as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix USN-6967-1?
To mitigate the risks of USN-6967-1, update the intel-microcode package to the specified versions for your Ubuntu release.
Who is affected by USN-6967-1?
USN-6967-1 affects local authenticated users on systems running vulnerable Intel® Core™ Ultra Processors with specific versions of Ubuntu.
What are the potential impacts of USN-6967-1?
The main impact of USN-6967-1 is the potential for a local authenticated user to escalate their privileges.
What versions of Ubuntu are impacted by USN-6967-1?
USN-6967-1 affects multiple Ubuntu versions, including 16.04, 18.04, 20.04, 22.04, and 24.04.