Red Hat Security Advisory: microcode_ctl security, bug fix, and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-31936 — kernel: microcode_ctl: Intel Xeon 6 Processors: Privilege escalation via improper memory range handling in SMM CVE-2025-35973 — kernel: hypervisor: Intel Processors: Privilege escalation in Ring 0 via improper value handling
🎯 Affected products3
- Red Hat Enterprise Linux BaseOS (v. 8)
- microcode_ctl-4:20260812-1.el8_10.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
- microcode_ctl-4:20260812-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: This vulnerability only affects systems using Intel Trust Domain Extensions (TDX) on Intel Xeon 6 processors. Systems not using Intel TDX are not vulnerable to this issue. Disabling Intel TDX, where feasible, removes the exposure to this vulnerability. Workaround: This is a hardware-level vulnerability in the affected Intel processors. There is no code-level fix available in Red Hat OpenShift sandboxed containers or other affected Red Hat components; the issue must be addressed at the processor firmware layer. Red Hat recommends that customers apply the latest CPU microcode or system firmware update from their hardware manufacturer. Intel has released microcode updates addressing this issue; see Intel Security Advisory INTEL-SA-01428 (https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html) for affected processor families and update guidance. Intel has indicated that a further Trusted Computing Base (TCB) recovery is planned for this issue. Red Hat will update this guidance if additional remediation steps become necessary once that information is available.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:65147
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2514104
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2514115
- externalhttps://issues.redhat.com/browse/RHEL-240770
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65147.json