RHEA-2023:6637HighCVSS 7.5
Red Hat Enhancement Advisory: microcode_ctl bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-21216 — kernel: Intel firmware update for insufficient granularity of access control in out-of-band management in some Intel Atom and Intel Xeon Scalable Processors CVE-2022-33196 — kernel: Intel firmware update for Incorrect default permissions in some memory controller configurations
🎯 Affected products3
- Red Hat Enterprise Linux BaseOS (v. 9)
- microcode_ctl-4:20230808-2.el9.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- microcode_ctl-4:20230808-2.el9.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to https://access.redhat.com/articles/11258 Note: a system reboot is necessary for this update to take effect.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHEA-2023:6637
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.3_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213022
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213124
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218104
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225681
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhea-2023_6637.json