CVE-2025-24495

Updated: 2026-02-27 03:23:13.829513

Description:

Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 5.6

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU microcode_ctl 20220809 5.6 MEDIUM Released CLSA-2025:1757692837 2025-09-12 19:37:32
CentOS 7 ELS microcode_ctl 2.1 5.6 MEDIUM Ignored 2025-10-31 01:04:34
CentOS 8.4 ELS microcode_ctl 20210216-1 5.6 MEDIUM Released CLSA-2025:1754381424 2025-08-06 03:13:03
CentOS 8.5 ELS microcode_ctl 20210608-1 5.6 MEDIUM Released CLSA-2025:1754381826 2025-08-06 03:13:04
CentOS Stream 8 ELS microcode_ctl 20230808 5.6 MEDIUM Released CLSA-2025:1754381655 2025-08-06 03:13:06
CloudLinux 7 ELS microcode_ctl 2.1 5.6 MEDIUM Ignored 2025-10-31 01:04:36
Oracle Linux 7 ELS microcode_ctl 2.1 5.6 MEDIUM Ignored 2025-10-31 01:04:36
RHEL 7 ELS microcode_ctl 2.1 5.6 MEDIUM Ignored 2025-10-31 01:04:35
Ubuntu 16.04 ELS intel-microcode 3.20201110.0 5.6 MEDIUM Released CLSA-2025:1754381695 2025-08-06 03:15:20
Ubuntu 18.04 ELS intel-microcode 3.20220809.0 5.6 MEDIUM Released CLSA-2025:1754381806 2025-08-06 03:15:31
Total: 11