CVE-2024-21823
Published: May 15, 2024Last modified: June 18, 2025
Description
Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow an authorized user to potentially enable denial of service via local access.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 7.5 | 
| Attack Vector | LOCAL | 
| Attack complexity | HIGH | 
| Privileges required | LOW | 
| User interaction | NONE | 
| Scope | CHANGED | 
| Confidentiality | NONE | 
| Integrity impact | HIGH | 
| Availability impact | HIGH | 
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Fixed (6.1.91-r0) | 
| Stream | linux-lts | Fixed (6.1.91-r0) | 
References
- http://www.openwall.com/lists/oss-security/2024/05/15/1
- https://lists.fedoraproject.org/archives/list/[email protected]/message/DW2MIOIMOFUSNLHLRYX23AFR36BMKD65/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/OTB4HWU2PTVW5NEYHHLOCXDKG3PYA534/
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01084.html