Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-35998

Опубликовано: 10 фев. 2026
Источник: redhat
CVSS3: 7.9
EPSS Низкий

Описание

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Missing protection mechanism for alternate hardware interface in the Intel® Quick Assist Technology for some Intel® Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Отчет

Actual for the Intel Xeon 6 with E-cores. Firmware or microcode update could be required (using BIOS or using other utilities by administrator). The bug accessible only to privileged users (like administrator can try to trigger it), so the impact is limited (means PR:H for the CVSS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10microcode_ctlAffected
Red Hat Enterprise Linux 6microcode_ctlNot affected
Red Hat Enterprise Linux 7microcode_ctlNot affected
Red Hat Enterprise Linux 8microcode_ctlNot affected
Red Hat Enterprise Linux 9microcode_ctlAffected
Red Hat Enterprise Linux 10.0 Extended Update Supportmicrocode_ctlFixedRHSA-2026:688807.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1220

EPSS

Процентиль: 4%
0.00151
Низкий

7.9 High

CVSS3

Связанные уязвимости

CVSS3: 7.9
nvd
7 месяцев назад

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 7.9
github
7 месяцев назад

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

EPSS

Процентиль: 4%
0.00151
Низкий

7.9 High

CVSS3