[Git][security-tracker-team/security-tracker][master] Track fixed version for intel-microcode updates

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat May 17 14:31:32 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
266726c6 by Salvatore Bonaccorso at 2025-05-17T15:31:04+02:00
Track fixed version for intel-microcode updates

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2232,37 +2232,37 @@ CVE-2024-55466 (An arbitrary file upload vulnerability in the Image Gallery of T
 CVE-2023-34732 (An issue in the userId parameter in the change password function of Fl ...)
 	NOT-FOR-US: Flytxt NEON-dX
 CVE-2025-20054 (Uncaught exception in the core management mechanism for some Intel(R)  ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01244.html
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
 CVE-2025-20103 (Insufficient resource pool in the core management mechanism for some I ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01244.html
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
 CVE-2024-45332 (Exposure of sensitive information caused by shared microarchitectural  ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
 	NOTE: https://comsec.ethz.ch/research/microarch/branch-privilege-injection/
 	NOTE: https://comsec.ethz.ch/wp-content/files/bprc_sec25.pdf
 CVE-2025-20623 (Exposure of sensitive information caused by shared microarchitectural  ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
 CVE-2024-43420 (Exposure of sensitive information caused by shared microarchitectural  ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
 CVE-2025-20012 (Incorrect behavior order for some Intel(R) Core\u2122 Ultra Processors ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01322.html
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
 CVE-2025-24495 (Incorrect initialization of resource in the branch prediction unit for ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01322.html
 	NOTE: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512
 CVE-2024-28956 (Exposure of Sensitive Information in Shared Microarchitectural Structu ...)
-	- intel-microcode <unfixed> (bug #1105172)
+	- intel-microcode 3.20250512.1 (bug #1105172)
 	- linux <unfixed>
 	- xen <unfixed> (bug #1105193)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/266726c6e33dcba566723add2ef8e98e41db034a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/266726c6e33dcba566723add2ef8e98e41db034a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250517/301dedf0/attachment.htm>


More information about the debian-security-tracker-commits mailing list