Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVSS Details
- CVSS 4.0 Base Score: 5.7 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-intel-ucode | Aug 8, 2025 | May 13, 2025 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-microcode_ctlamazon-linux-ami-2-upgrade-microcode_ctl-debuginfo | May 30, 2025 | May 13, 2025 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-microcode-ctl | Jun 3, 2025 | May 13, 2025 | |
| Debian | debian-upgrade-intel-microcode | May 15, 2025 | May 13, 2025 | |
| Dell Poweredge Dsa2025156 | dell-poweredge-upgrade-latest | Oct 23, 2025 | May 13, 2025 | |
| Nutanix Ahv | nutanix-ahv-upgrade-latest | Jun 5, 2026 | Dec 15, 2025 | |
| Redhat_linux | redhat-upgrade-microcode_ctlredhat-upgrade-microcode_ctl-debuginfo | Jul 4, 2025 | May 13, 2025 | |
| Rocky_linux | rocky-upgrade-microcode_ctl | Feb 5, 2026 | Jul 29, 2025 | |
| Suse | — | suse-upgrade-microcode_ctlsuse-upgrade-ucode-intel | Dec 5, 2025 | May 22, 2025 |
| Ubuntu | ubuntu-pro-upgrade-intel-microcodeubuntu-upgrade-intel-microcode | May 28, 2025 | May 13, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub