GHSA-qfxp-65r3-gfv7 · Severity: medium — TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an...
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Conclusion & alert: CVE-2019-11135 is rated Moderate Risk (45.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.32%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-24 | 0.24% | 0.32% | +0.08% |
| 2 | 2025-10-28 | 0.26% | 0.24% | -0.02% |
| 3 | 2025-10-27 | — | 0.26% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.0 | 4.0 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.0 | 4.0 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 2.1 | 2.0 | LOW |
|
3.9 | 2.9 | [email protected] |
GHSA-qfxp-65r3-gfv7 · Severity: medium — TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an...
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2019-11135: 2 source package rows (intel-ucode, xen); 31 state rows across 10 repos (3.10-main, 3.11-main, 3.12-main, 3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 31, open 0. | https://security.alpinelinux.org/vuln/CVE-2019-11135 |
debian
|
not yet assigned | CVE-2019-11135 not yet assigned priority: Debian including 3 source packages (intel-microcode, linux, xen), 15 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 15. | https://security-tracker.debian.org/tracker/CVE-2019-11135 |
gentoo
|
high | CVE-2019-11135: 1 GLSA(s) (202003-56), 2 atom(s) (app-emulation/xen, app-emulation/xen-tools); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2019-11135 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-11135 |
suse
|
medium | CVE-2019-11135 severity moderate: SUSE including 1885 source package names (2.1.3-6.67:kernel-default-base-6.4.0-32.1.21.10, 2.1.3-7.44:kernel-default-6.4.0-32.1, …), 3400 product×package rows across 273 product lines (Container suse/sl-micro/6.0/base-os-container, Container suse/sl-micro/6.0/kvm-os-container, … (273 product lines)): Fixed 2463, Known Not Affected 706, Known Affected 231. | https://www.suse.com/security/cve/CVE-2019-11135/ |
ubuntu
|
high | CVE-2019-11135 high priority: Ubuntu including 112 source packages (intel-microcode, linux, …), 1161 status rows across 13 suites (bionic, disco, eoan, focal, groovy, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 809, released 170, not-affected 165, ignored 15, needed 1, needs-triage 1. | https://ubuntu.com/security/CVE-2019-11135 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| opensuse | leap | 15.0 | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| fedoraproject | fedora | 30 | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| slackware | slackware | 14.2 | cpe:2.3:a:slackware:slackware:14.2:*:*:*:*:*:*:* |
| hp | apollo_4200_firmware | < 2.20 | cpe:2.3:o:hp:apollo_4200_firmware:*:*:*:*:*:*:*:* |
| hp | apollo_2000_firmware | < 2.20 | cpe:2.3:o:hp:apollo_2000_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_bl460c_firmware | < 2.20 | cpe:2.3:o:hp:proliant_bl460c_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl580_firmware | < 2.20 | cpe:2.3:o:hp:proliant_dl580_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl560_firmware | < 2.20 | cpe:2.3:o:hp:proliant_dl560_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl380_firmware | < 2.20 | cpe:2.3:o:hp:proliant_dl380_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl360_firmware | < 2.20 | cpe:2.3:o:hp:proliant_dl360_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl180_firmware | < 2.20 | cpe:2.3:o:hp:proliant_dl180_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl160_firmware | < 2.20 | cpe:2.3:o:hp:proliant_dl160_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl120_firmware | < 2.20 | cpe:2.3:o:hp:proliant_dl120_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_dl20_firmware | < 2.10 | cpe:2.3:o:hp:proliant_dl20_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_ml350_firmware | < 2.20 | cpe:2.3:o:hp:proliant_ml350_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_ml110_firmware | < 2.20 | cpe:2.3:o:hp:proliant_ml110_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_ml30_firmware | < 2.10 | cpe:2.3:o:hp:proliant_ml30_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_xl450_firmware | < 2.20 | cpe:2.3:o:hp:proliant_xl450_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_xl270d_firmware | < 2.20 | cpe:2.3:o:hp:proliant_xl270d_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_xl230k_firmware | < 2.20 | cpe:2.3:o:hp:proliant_xl230k_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_xl190r_firmware | < 2.20 | cpe:2.3:o:hp:proliant_xl190r_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_xl170r_firmware | < 2.20 | cpe:2.3:o:hp:proliant_xl170r_firmware:*:*:*:*:*:*:*:* |
| hp | synergy_480_firmware | < 2.20 | cpe:2.3:o:hp:synergy_480_firmware:*:*:*:*:*:*:*:* |
| hp | synergy_660_firmware | < 2.20 | cpe:2.3:o:hp:synergy_660_firmware:*:*:*:*:*:*:*:* |
| hp | proliant_e910_firmware | < 2.20 | cpe:2.3:o:hp:proliant_e910_firmware:*:*:*:*:*:*:*:* |
| intel | core_i7-10510y_firmware | — | cpe:2.3:o:intel:core_i7-10510y_firmware:-:*:*:*:*:*:*:* |
| intel | core_i5-10310y_firmware | — | cpe:2.3:o:intel:core_i5-10310y_firmware:-:*:*:*:*:*:*:* |
| intel | core_i5-10210y_firmware | — | cpe:2.3:o:intel:core_i5-10210y_firmware:-:*:*:*:*:*:*:* |
| intel | core_i5-10110y_firmware | — | cpe:2.3:o:intel:core_i5-10110y_firmware:-:*:*:*:*:*:*:* |
| intel | core_i7-8500y_firmware | — | cpe:2.3:o:intel:core_i7-8500y_firmware:-:*:*:*:*:*:*:* |
| intel | core_i5-8310y_firmware | — | cpe:2.3:o:intel:core_i5-8310y_firmware:-:*:*:*:*:*:*:* |
| intel | core_i5-8210y_firmware | — | cpe:2.3:o:intel:core_i5-8210y_firmware:-:*:*:*:*:*:*:* |
| intel | core_i5-8200y_firmware | — | cpe:2.3:o:intel:core_i5-8200y_firmware:-:*:*:*:*:*:*:* |
| intel | core_m3-8100y_firmware | — | cpe:2.3:o:intel:core_m3-8100y_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8253_firmware | — | cpe:2.3:o:intel:xeon_8253_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8256_firmware | — | cpe:2.3:o:intel:xeon_8256_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8260_firmware | — | cpe:2.3:o:intel:xeon_8260_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8260l_firmware | — | cpe:2.3:o:intel:xeon_8260l_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8260m_firmware | — | cpe:2.3:o:intel:xeon_8260m_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8260y_firmware | — | cpe:2.3:o:intel:xeon_8260y_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8268_firmware | — | cpe:2.3:o:intel:xeon_8268_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8270_firmware | — | cpe:2.3:o:intel:xeon_8270_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8276_firmware | — | cpe:2.3:o:intel:xeon_8276_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8276l_firmware | — | cpe:2.3:o:intel:xeon_8276l_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8276m_firmware | — | cpe:2.3:o:intel:xeon_8276m_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8280_firmware | — | cpe:2.3:o:intel:xeon_8280_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8280l_firmware | — | cpe:2.3:o:intel:xeon_8280l_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_8280m_firmware | — | cpe:2.3:o:intel:xeon_8280m_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_9220_firmware | — | cpe:2.3:o:intel:xeon_9220_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_9221_firmware | — | cpe:2.3:o:intel:xeon_9221_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_9222_firmware | — | cpe:2.3:o:intel:xeon_9222_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_9242_firmware | — | cpe:2.3:o:intel:xeon_9242_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_9282_firmware | — | cpe:2.3:o:intel:xeon_9282_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5215_firmware | — | cpe:2.3:o:intel:xeon_5215_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5215l_firmware | — | cpe:2.3:o:intel:xeon_5215l_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5215m_firmware | — | cpe:2.3:o:intel:xeon_5215m_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5215r_firmware | — | cpe:2.3:o:intel:xeon_5215r_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5217_firmware | — | cpe:2.3:o:intel:xeon_5217_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5218_firmware | — | cpe:2.3:o:intel:xeon_5218_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5218b_firmware | — | cpe:2.3:o:intel:xeon_5218b_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5218n_firmware | — | cpe:2.3:o:intel:xeon_5218n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5218t_firmware | — | cpe:2.3:o:intel:xeon_5218t_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5220_firmware | — | cpe:2.3:o:intel:xeon_5220_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5220r_firmware | — | cpe:2.3:o:intel:xeon_5220r_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5220s_firmware | — | cpe:2.3:o:intel:xeon_5220s_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5220t_firmware | — | cpe:2.3:o:intel:xeon_5220t_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_5222_firmware | — | cpe:2.3:o:intel:xeon_5222_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6222v_firmware | — | cpe:2.3:o:intel:xeon_6222v_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6226_firmware | — | cpe:2.3:o:intel:xeon_6226_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6230_firmware | — | cpe:2.3:o:intel:xeon_6230_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6230n_firmware | — | cpe:2.3:o:intel:xeon_6230n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6230t_firmware | — | cpe:2.3:o:intel:xeon_6230t_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6234_firmware | — | cpe:2.3:o:intel:xeon_6234_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6238_firmware | — | cpe:2.3:o:intel:xeon_6238_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6238l_firmware | — | cpe:2.3:o:intel:xeon_6238l_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6238m_firmware | — | cpe:2.3:o:intel:xeon_6238m_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6238t_firmware | — | cpe:2.3:o:intel:xeon_6238t_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_6240_firmware | — | cpe:2.3:o:intel:xeon_6240_firmware:-:*:*:*:*:*:*:* |