Opened 8 months ago

Closed 8 months ago

#22779 closed enhancement (fixed)

intel-microcode-20260210

Reported by: Xi Ruoyao Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New microcode release with some security advisories.

Change History (3)

comment:1 by Douglas R. Reno, 8 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 8 months ago

This has security fixes for two vulnerabilities:

  • CVE-2024-24853 (Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel® Processor may allow a privileged user to potentially enable escalation of privilege via local access.). Rated as 7.3 high, and it's a privilege escalation vulnerability. This appears to affect the 6th-11th generation Intel CPUs on the consumer side.
  • CVE-2025-31648 (Improper handling of values in the microcode flow for some Intel® Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.). Rated as 1.9 Low.

comment:3 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at b1eb62771c028bcb5d1c78ecae719d9593f493ae

SA-12.4-092 issued

Note: See TracTickets for help on using tickets.