{"id":"MGASA-2025-0160","summary":"Updated microcode packages fix security vulnerabilities","details":"Exposure of Sensitive Information in Shared Microarchitectural\nStructures during Transient Execution for some Intel® Processors may\nallow an authenticated user to potentially enable information disclosure\nvia local access. (CVE-2024-28956)\nInsufficient resource pool in the core management mechanism for some\nIntel® Processors may allow an authenticated user to potentially enable\ndenial of service via local access. (CVE-2025-20103)\nUncaught exception in the core management mechanism for some Intel®\nProcessors may allow an authenticated user to potentially enable denial\nof service via local access. (CVE-2025-20054)\nExposure of sensitive information caused by shared microarchitectural\npredictor state that influences transient execution for some Intel Atom®\nprocessors may allow an authenticated user to potentially enable\ninformation disclosure via local access. (CVE-2024-43420)\nExposure of sensitive information caused by shared microarchitectural\npredictor state that influences transient execution for some Intel®\nCore™ processors (10th Generation) may allow an authenticated user to\npotentially enable information disclosure via local access.\n(CVE-2025-20623)\nExposure of sensitive information caused by shared microarchitectural\npredictor state that influences transient execution in the indirect\nbranch predictors for some Intel® Processors may allow an authenticated\nuser to potentially enable information disclosure via local access.\n(CVE-2024-45332)\nIncorrect initialization of resource in the branch prediction unit for\nsome Intel® Core™ Ultra Processors may allow an authenticated user to\npotentially enable information disclosure via local access.\n(CVE-2025-24495)\nIncorrect behavior order for some Intel® Core™ Ultra Processors may\nallow an unauthenticated user to potentially enable information\ndisclosure via physical access. (CVE-2025-20012)\n","modified":"2026-04-16T00:10:30.153664860Z","published":"2025-05-23T20:06:42Z","upstream":["CVE-2024-28956","CVE-2024-43420","CVE-2024-45332","CVE-2025-20012","CVE-2025-20054","CVE-2025-20103","CVE-2025-20623","CVE-2025-24495"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0160.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34279"},{"type":"WEB","url":"https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250512"}],"affected":[{"package":{"name":"microcode","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/microcode?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.20250512-1.mga9.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0160.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}