microcode_ctl vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the microcode_ctl package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Insufficient Resource Pool

*
  • M
Uncaught Exception

*
  • M
CVE-2025-20623

*
  • M
Hardware Features Enable Physical Attacks from Software

*
  • M
CVE-2024-45332

*
  • M
CVE-2024-43420

*
  • M
Incorrect Behavior Order

*
  • M
CVE-2025-24495

*
  • M
Improper Access Control

*
  • M
Improper Finite State Machines (FSMs) in Hardware Logic

*
  • M
Improper Finite State Machines (FSMs) in Hardware Logic

*
  • M
Insufficient Granularity of Access Control

*
  • M
Improper Initialization

*
  • H
Improper Input Validation

*
  • H
Improper Input Validation

*
  • H
Improper Input Validation

*
  • M
Improper Input Validation

*
  • H
Improper Input Validation

*
  • H
Improper Input Validation

*
  • M
Improper Finite State Machines (FSMs) in Hardware Logic

*
  • M
Resource Exhaustion

*
  • L
Information Exposure

*
  • M
Protection Mechanism Failure

*
  • M
Incorrect Calculation

*
  • M
Non-Transparent Sharing of Microarchitectural Resources

*
  • M
Protection Mechanism Failure

*
  • M
CVE-2023-28746

*
  • H
Unauthorized Error Injection Can Degrade Hardware Redundancy

<4:20220809-2.20230808.2.el8_8
  • H
Expected Behavior Violation

<4:20190618-1.20191112.1.el8_1
  • M
CVE-2022-38090

*
  • M
Incorrect Calculation

*
  • H
Incorrect Default Permissions

<4:20230808-2.el8
  • H
CVE-2022-21216

<4:20230808-2.el8
  • M
Out-of-bounds Read

*
  • M
CVE-2021-0127

*
  • M
Improper Initialization

*
  • H
Information Exposure

<4:20210216-1.20210525.1.el8_4
  • H
Information Exposure

<4:20210216-1.20210608.1.el8_4
  • H
Information Exposure

<4:20210216-1.20210608.1.el8_4
  • H
Incomplete Cleanup

<4:20210216-1.20210608.1.el8_4
  • H
Improper Cross-boundary Removal of Sensitive Data

<4:20210216-1.20210608.1.el8_4
  • H
Information Exposure

<4:20210216-1.20210608.1.el8_4
  • H
Information Exposure

<4:20210216-1.20210608.1.el8_4
  • H
Information Exposure

<4:20210216-1.20210608.1.el8_4
  • H
Information Exposure

<4:20210216-1.20210608.1.el8_4
  • H
Insufficient Granularity of Access Control

<4:20190618-1.20191112.1.el8_1
  • H
Improper Cross-boundary Removal of Sensitive Data

<4:20210216-1.20210608.1.el8_4