CVE Vulnerabilities

CVE-2025-20103

Insufficient Resource Pool

Published: May 13, 2025 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.

Weakness

The product’s resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.

Affected Software

NameVendorStart VersionEnd Version
Intel-microcodeUbuntudevel*
Intel-microcodeUbuntuesm-infra-legacy/trusty*
Intel-microcodeUbuntuesm-infra/bionic*
Intel-microcodeUbuntuesm-infra/focal*
Intel-microcodeUbuntuesm-infra/xenial*
Intel-microcodeUbuntufocal*
Intel-microcodeUbuntujammy*
Intel-microcodeUbuntunoble*
Intel-microcodeUbuntuoracular*
Intel-microcodeUbuntuplucky*
Intel-microcodeUbuntuupstream*

Potential Mitigations

References