Security update for ucode-intel
Announcement ID: | SUSE-SU-2025:03053-1 |
---|---|
Release Date: | 2025-09-02T17:42:28Z |
Rating: | important |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves seven vulnerabilities can now be installed.
Description:
This update for ucode-intel fixes the following issues:
-
Intel CPU Microcode was updated to the 20250812 release (bsc#1248438)
- CVE-2025-20109: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-22840: Sequence of processor instructions leads to unexpected behavior for some Intel Xeon 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access
- CVE-2025-22839: Insufficient granularity of access control in the OOB-MSM for some Intel Xeon 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
- CVE-2025-22889: Improper handling of overlap between protected memory ranges for some Intel Xeon 6 processor with Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-20053: Improper buffer restrictions for some Intel Xeon Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-26403: Out-of-bounds write in the memory subsystem for some Intel Xeon 6 processors when using Intel SGX or Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-32086: Improperly implemented security check for standard in the DDRIO configuration for some Intel Xeon 6 Processors when using Intel SGX or Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.
- Update for functional issues.
- Updated Platforms:
Processor Stepping F-M-S/PI Old Ver New Ver Products ARL-H A1 06-c5-02/82 00000118 00000119 Core Ultra Processor (Series 2) ARL-S/HX (8P) B0 06-c6-02/82 00000118 00000119 Core Ultra Processor (Series 2) EMR-SP A1 06-cf-02/87 210002a9 210002b3 Xeon Scalable Gen5 GNR-AP/SP B0 06-ad-01/95 010003a2 010003d0 Xeon Scalable Gen6 GNR-AP/SP H0 06-ad-01/20 0a0000d1 0a000100 Xeon Scalable Gen6 ICL-D B0 06-6c-01/10 010002d0 010002e0 Xeon D-17xx, D-27xx ICX-SP Dx/M1 06-6a-06/87 0d000404 0d000410 Xeon Scalable Gen3 LNL B0 06-bd-01/80 0000011f 00000123 Core Ultra 200 V Series Processor MTL C0 06-aa-04/e6 00000024 00000025 Core™ Ultra Processor RPL-H/P/PX 6+8 J0 06-ba-02/e0 00004128 00004129 Core Gen13 RPL-U 2+8 Q0 06-ba-03/e0 00004128 00004129 Core Gen13 SPR-HBM Bx 06-8f-08/10 2c0003f7 2c000401 Xeon Max SPR-SP E4/S2 06-8f-07/87 2b000639 2b000643 Xeon Scalable Gen4 SPR-SP E5/S3 06-8f-08/87 2b000639 2b000643 Xeon Scalable Gen4 SRF-SP C0 06-af-03/01 03000341 03000362 Xeon 6700-Series Processors with E-Cores
New Disclosures Updated in Prior Releases: All ADL, RPL, SPR, EMR, MTL, ARL Microcode patches previously released in May 2025.
Special Instructions and Notes:
- Please reboot the system after installing this update.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-3053=1
-
SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-3053=1
-
SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-3053=1
-
SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-3053=1
-
SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-3053=1
-
SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2025-3053=1
-
Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3053=1
-
Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3053=1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3053=1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3053=1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3053=1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3053=1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3053=1
-
SUSE Linux Enterprise Server 15 SP3 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3053=1
-
SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3053=1
-
SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3053=1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP3
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3053=1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3053=1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3053=1
-
SUSE Manager Proxy 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3053=1
-
SUSE Manager Retail Branch Server 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.3-LTS-2025-3053=1
-
SUSE Manager Server 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3053=1
-
SUSE Enterprise Storage 7.1
zypper in -t patch SUSE-Storage-7.1-2025-3053=1
-
SUSE Linux Enterprise Micro 5.1
zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-3053=1
-
SUSE Linux Enterprise Micro 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-3053=1
-
SUSE Linux Enterprise Micro for Rancher 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-3053=1
Package List:
-
openSUSE Leap 15.6 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro 5.3 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro 5.4 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro 5.5 (x86_64)
- ucode-intel-20250812-150200.59.1
-
Basesystem Module 15-SP6 (x86_64)
- ucode-intel-20250812-150200.59.1
-
Basesystem Module 15-SP7 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Server 15 SP3 LTSS (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Manager Proxy 4.3 LTS (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Manager Retail Branch Server 4.3 LTS (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Manager Server 4.3 LTS (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Enterprise Storage 7.1 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro 5.1 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro 5.2 (x86_64)
- ucode-intel-20250812-150200.59.1
-
SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64)
- ucode-intel-20250812-150200.59.1
References:
- https://www.suse.com/security/cve/CVE-2025-20053.html
- https://www.suse.com/security/cve/CVE-2025-20109.html
- https://www.suse.com/security/cve/CVE-2025-22839.html
- https://www.suse.com/security/cve/CVE-2025-22840.html
- https://www.suse.com/security/cve/CVE-2025-22889.html
- https://www.suse.com/security/cve/CVE-2025-26403.html
- https://www.suse.com/security/cve/CVE-2025-32086.html
- https://bugzilla.suse.com/show_bug.cgi?id=1248438