ELA-1242-1 intel-microcode security update

Microcode update

2024-11-24
Packageintel-microcode
Version3.20240910.1~deb8u1 (jessie), 3.20240910.1~deb9u1 (stretch), 3.20240910.1~deb10u1 (buster)
Related CVEs CVE-2024-23984 CVE-2024-24968


A microcode update has been released for Intel processors, addressing multiple vulnerabilties which potentially could cause information disclosue or local DoS.

CVE-2024-23984

Observable discrepancy in RAPL interface for some Intel(R)
Processors may allow a privileged user to potentially enable
information disclosure via local access.

CVE-2024-24968

Improper finite state machines (FSMs) in hardware logic in some
Intel(R) Processors may allow an privileged user to potentially
enable a denial of service via local access.


For Debian 10 buster, these problems have been fixed in version 3.20240910.1~deb10u1.

For Debian 8 jessie, these problems have been fixed in version 3.20240910.1~deb8u1.

For Debian 9 stretch, these problems have been fixed in version 3.20240910.1~deb9u1.

We recommend that you upgrade your intel-microcode packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.