RHSA-2025:7043MediumCVSS 6.5

Red Hat Security Advisory: microcode_ctl security update

Published
May 13, 2025
Last Modified
August 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-28047 — microcode_ctl: Improper input validation in UEFI firmware CVE-2024-31157 — microcode_ctl: Improper initialization in UEFI firmware OutOfBandXML module CVE-2024-39279 — microcode_ctl: Insufficient granularity of access control in UEFI firmware

🎯 Affected products3

  • Red Hat Enterprise Linux BaseOS (v. 9)
  • microcode_ctl-4:20250211-1.el9_6.noarch as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • microcode_ctl-4:20250211-1.el9_6.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (8)