Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-35973

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

A flaw was found in Intel(R) Processors within Ring 0, affecting the kernel, hypervisor, and bare metal operating systems. Improper handling of values may allow an authorized adversary with privileged user access to perform a local, high-complexity attack. This can lead to an escalation of privilege, potentially resulting in high impact to the confidentiality and integrity of the system.

Отчет

Red Hat is aware of a hardware vulnerability affecting some Intel processors that could allow a local attacker who already has privileged access to escalate privileges by exploiting improper handling of internal processor values during Ring 0 execution. In the most severe case, this could allow a privileged workload running inside a virtual machine to escalate access into the underlying hypervisor. Exploitation requires local access, existing privileged access, and a high degree of attack complexity, including detailed knowledge of the processor's internal behavior. Red Hat products that provide workload isolation using a hypervisor, such as Red Hat OpenShift sandboxed containers (which uses Kata Containers), are assessed as Important severity because of the potential impact on isolation between different tenants' workloads if the underlying processor is vulnerable and has not been updated.

Меры по смягчению последствий

This is a hardware-level vulnerability in the affected Intel processors. There is no code-level fix available in Red Hat OpenShift sandboxed containers or other affected Red Hat components; the issue must be addressed at the processor firmware layer. Red Hat recommends that customers apply the latest CPU microcode or system firmware update from their hardware manufacturer. Intel has released microcode updates addressing this issue; see Intel Security Advisory INTEL-SA-01428 (https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html) for affected processor families and update guidance. Intel has indicated that a further Trusted Computing Base (TCB) recovery is planned for this issue. Red Hat will update this guidance if additional remediation steps become necessary once that information is available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Will not fix
Red Hat Enterprise Linux 10kernelAffected
Red Hat Enterprise Linux 10libkrunNot affected
Red Hat Enterprise Linux 6kernelAffected
Red Hat Enterprise Linux 7kernelAffected
Red Hat Enterprise Linux 7kernel-rtAffected
Red Hat Enterprise Linux 8kernelAffected
Red Hat Enterprise Linux 8kernel-rtWill not fix
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2514104kernel: hypervisor: Intel Processors: Privilege escalation in Ring 0 via improper value handling

EPSS

Процентиль: 1%
0.00102
Низкий

7.2 High

CVSS3

Связанные уязвимости

ubuntu
15 дней назад

Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

nvd
15 дней назад

Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

debian
15 дней назад

Improper handling of values for some Intel(R) Processors within Ring 0 ...

github
15 дней назад

Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

EPSS

Процентиль: 1%
0.00102
Низкий

7.2 High

CVSS3