RHEA-2023:4636HighCVSS 7.5
Red Hat Enhancement Advisory: microcode_ctl bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-21216 — kernel: Intel firmware update for insufficient granularity of access control in out-of-band management in some Intel Atom and Intel Xeon Scalable Processors CVE-2022-33196 — kernel: Intel firmware update for Incorrect default permissions in some memory controller configurations
🎯 Affected products12
- Red Hat Enterprise Linux Client (v. 7)
- Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux Workstation (v. 7)
- microcode_ctl-2:2.1-73.16.el7_9.src as a component of Red Hat Enterprise Linux Client (v. 7)
- microcode_ctl-2:2.1-73.16.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7)
- microcode_ctl-2:2.1-73.16.el7_9.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
- microcode_ctl-2:2.1-73.16.el7_9.x86_64 as a component of Red Hat Enterprise Linux Client (v. 7)
- microcode_ctl-2:2.1-73.16.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
- microcode_ctl-2:2.1-73.16.el7_9.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
- microcode_ctl-debuginfo-2:2.1-73.16.el7_9.x86_64 as a component of Red Hat Enterprise Linux Client (v. 7)
- microcode_ctl-debuginfo-2:2.1-73.16.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
- microcode_ctl-debuginfo-2:2.1-73.16.el7_9.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258