RHEA-2023:7117HighCVSS 7.5
Red Hat Enhancement Advisory: microcode_ctl bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-21216 — kernel: Intel firmware update for insufficient granularity of access control in out-of-band management in some Intel Atom and Intel Xeon Scalable Processors CVE-2022-33196 — kernel: Intel firmware update for Incorrect default permissions in some memory controller configurations
🎯 Affected products3
- Red Hat Enterprise Linux BaseOS (v. 8)
- microcode_ctl-4:20230808-2.el8.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- microcode_ctl-4:20230808-2.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHEA-2023:7117
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.9_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213125
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231065
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhea-2023_7117.json