CVE Vulnerabilities

CVE-2024-21853

Improper Finite State Machines (FSMs) in Hardware Logic

Published: Nov 13, 2024 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.7 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local access.

Weakness

Faulty finite state machines (FSMs) in the hardware logic allow an attacker to put the system in an undefined state, to cause a denial of service (DoS) or gain privileges on the victim’s system.

Affected Software

NameVendorStart VersionEnd Version
Intel-microcodeUbuntudevel*
Intel-microcodeUbuntuesm-infra-legacy/trusty*
Intel-microcodeUbuntuesm-infra/bionic*
Intel-microcodeUbuntuesm-infra/focal*
Intel-microcodeUbuntuesm-infra/xenial*
Intel-microcodeUbuntufocal*
Intel-microcodeUbuntujammy*
Intel-microcodeUbuntunoble*
Intel-microcodeUbuntuoracular*
Intel-microcodeUbuntutrusty/esm*
Intel-microcodeUbuntuupstream*

Extended Description

The functionality and security of the system heavily depend on the implementation of FSMs. FSMs can be used to indicate the current security state of the system. Lots of secure data operations and data transfers rely on the state reported by the FSM.

Potential Mitigations

References