Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:03053-1

Опубликовано: 02 сент. 2025
Источник: suse-cvrf

Описание

Security update for ucode-intel

This update for ucode-intel fixes the following issues:

  • Intel CPU Microcode was updated to the 20250812 release (bsc#1248438)

    • CVE-2025-20109: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

    • CVE-2025-22840: Sequence of processor instructions leads to unexpected behavior for some Intel Xeon 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access

    • CVE-2025-22839: Insufficient granularity of access control in the OOB-MSM for some Intel Xeon 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.

    • CVE-2025-22889: Improper handling of overlap between protected memory ranges for some Intel Xeon 6 processor with Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.

    • CVE-2025-20053: Improper buffer restrictions for some Intel Xeon Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access.

    • CVE-2025-26403: Out-of-bounds write in the memory subsystem for some Intel Xeon 6 processors when using Intel SGX or Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.

    • CVE-2025-32086: Improperly implemented security check for standard in the DDRIO configuration for some Intel Xeon 6 Processors when using Intel SGX or Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.

    • Update for functional issues.

    • Updated Platforms:

      ProcessorSteppingF-M-S/PIOld VerNew VerProducts
      ARL-HA106-c5-02/820000011800000119Core Ultra Processor (Series 2)
      ARL-S/HX (8P)B006-c6-02/820000011800000119Core Ultra Processor (Series 2)
      EMR-SPA106-cf-02/87210002a9210002b3Xeon Scalable Gen5
      GNR-AP/SPB006-ad-01/95010003a2010003d0Xeon Scalable Gen6
      GNR-AP/SPH006-ad-01/200a0000d10a000100Xeon Scalable Gen6
      ICL-DB006-6c-01/10010002d0010002e0Xeon D-17xx, D-27xx
      ICX-SPDx/M106-6a-06/870d0004040d000410Xeon Scalable Gen3
      LNLB006-bd-01/800000011f00000123Core Ultra 200 V Series Processor
      MTLC006-aa-04/e60000002400000025Core™ Ultra Processor
      RPL-H/P/PX 6+8J006-ba-02/e00000412800004129Core Gen13
      RPL-U 2+8Q006-ba-03/e00000412800004129Core Gen13
      SPR-HBMBx06-8f-08/102c0003f72c000401Xeon Max
      SPR-SPE4/S206-8f-07/872b0006392b000643Xeon Scalable Gen4
      SPR-SPE5/S306-8f-08/872b0006392b000643Xeon Scalable Gen4
      SRF-SPC006-af-03/010300034103000362Xeon 6700-Series Processors with E-Cores

    New Disclosures Updated in Prior Releases: All ADL, RPL, SPR, EMR, MTL, ARL Microcode patches previously released in May 2025.

Список пакетов

SUSE Enterprise Storage 7.1
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Micro 5.1
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Micro 5.2
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Micro 5.3
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Micro 5.4
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Micro 5.5
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Server 15 SP3-LTSS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Server 15 SP4-LTSS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Server 15 SP5-LTSS
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
ucode-intel-20250812-150200.59.1
SUSE Manager Proxy LTS 4.3
ucode-intel-20250812-150200.59.1
SUSE Manager Server LTS 4.3
ucode-intel-20250812-150200.59.1
openSUSE Leap 15.6
ucode-intel-20250812-150200.59.1

Описание

Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Enterprise Storage 7.1:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:ucode-intel-20250812-150200.59.1

Ссылки

Описание

Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Enterprise Storage 7.1:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:ucode-intel-20250812-150200.59.1

Ссылки

Описание

Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.


Затронутые продукты
SUSE Enterprise Storage 7.1:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:ucode-intel-20250812-150200.59.1

Ссылки

Описание

Sequence of processor instructions leads to unexpected behavior for some Intel(R) Xeon(R) 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access


Затронутые продукты
SUSE Enterprise Storage 7.1:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:ucode-intel-20250812-150200.59.1

Ссылки

Описание

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Enterprise Storage 7.1:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:ucode-intel-20250812-150200.59.1

Ссылки

Описание

Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Enterprise Storage 7.1:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:ucode-intel-20250812-150200.59.1

Ссылки

Описание

Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Enterprise Storage 7.1:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:ucode-intel-20250812-150200.59.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:ucode-intel-20250812-150200.59.1

Ссылки
Уязвимость SUSE-SU-2025:03053-1