SB2025052989 - SUSE update for ucode-intel
Published: May 29, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 secuirty vulnerabilities.
1) Resource management error (CVE-ID: CVE-2024-28956)
The vulnerability allows a malicious guest to escalate privileges on the system.
The vulnerability exists due to an error in the hardware support for prediction-domain isolation dubbed "Indirect Target Selection". A malicious guest can infer the contents of arbitrary host memory, including memory assigned to other guests.
2) Information disclosure (CVE-ID: CVE-2024-43420)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to shared microarchitectural predictor state that influences transient execution. A local user can gain access to sensitive information.
3) Information disclosure (CVE-ID: CVE-2024-45332)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to shared microarchitectural predictor state that influences transient execution. A local user can gain access to sensitive information.
4) Incorrect behavior order (CVE-ID: CVE-2025-20012)
The vulnerability allows a local attacker to gain access to sensitive information on the system. The vulnerability exists due to incorrect behavior order. An attacker with physical access can disclose sensitive information on the target system.5) Uncaught Exception (CVE-ID: CVE-2025-20054)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an uncaught exception in the core management mechanism for some Intel Processors. A local user can perform a denial of service (DoS) attack.
6) Resource management error (CVE-ID: CVE-2025-20103)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient resource pool in the core management mechanism for some Intel Processors. A local user can perform a denial of service (DoS) attack.
7) Information disclosure (CVE-ID: CVE-2025-20623)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to shared microarchitectural predictor state that influences transient execution. A local user can gain access to sensitive information.
8) Missing initialization of resource (CVE-ID: CVE-2025-24495)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to incorrect initialization of resource in the branch prediction unit. A local user can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.