rpm package
opensuse/ucode-intel&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ucode-intel&distro=openSUSE%20Tumbleweed
Vulnerabilities (76)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-20917 | Med | — | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity at | |
| CVE-2026-20760 | Med | — | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of p | |
| CVE-2026-20716 | Hig | 7.0 | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially | |
| CVE-2026-20713 | Med | — | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may pot | |
| CVE-2026-20707 | Med | — | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of | |
| CVE-2025-35973 | Med | — | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result ma | |
| CVE-2025-31938 | Med | — | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. Thi | |
| CVE-2025-31936 | Med | 5.7 | < 20260812-1.1 | 20260812-1.1 | Aug 11, 2026 | Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privil | |
| CVE-2025-35979 | Med | — | < 20260512-1.1 | 20260512-1.1 | May 12, 2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated | |
| CVE-2025-31648 | Low | 3.9 | < 20260210-1.1 | 20260210-1.1 | Feb 10, 2026 | Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially | |
| CVE-2025-32086 | Hig | 7.2 | < 20250812-1.1 | 20250812-1.1 | Aug 12, 2025 | Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. | |
| CVE-2025-26403 | Hig | 7.2 | < 20250812-1.1 | 20250812-1.1 | Aug 12, 2025 | Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. | |
| CVE-2025-22889 | Hig | 7.9 | < 20250812-1.1 | 20250812-1.1 | Aug 12, 2025 | Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. | |
| CVE-2025-22840 | Hig | 7.4 | < 20250812-1.1 | 20250812-1.1 | Aug 12, 2025 | Sequence of processor instructions leads to unexpected behavior for some Intel(R) Xeon(R) 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access | |
| CVE-2025-22839 | Hig | 7.5 | < 20250812-1.1 | 20250812-1.1 | Aug 12, 2025 | Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access. | |
| CVE-2025-20109 | Hig | 7.8 | < 20250812-1.1 | 20250812-1.1 | Aug 12, 2025 | Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| CVE-2025-20053 | Hig | 7.2 | < 20250812-1.1 | 20250812-1.1 | Aug 12, 2025 | Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access. | |
| CVE-2025-24495 | Med | 5.6 | < 20250512-1.1 | 20250512-1.1 | May 13, 2025 | Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| CVE-2025-20623 | Med | 5.6 | < 20250512-1.1 | 20250512-1.1 | May 13, 2025 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Core™ processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access. | |
| CVE-2025-20103 | Med | 6.5 | < 20250512-1.1 | 20250512-1.1 | May 13, 2025 | Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access. |
- affected < 20260812-1.1fixed 20260812-1.1
Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity at
- affected < 20260812-1.1fixed 20260812-1.1
Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of p
- affected < 20260812-1.1fixed 20260812-1.1
Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially
- affected < 20260812-1.1fixed 20260812-1.1
Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may pot
- affected < 20260812-1.1fixed 20260812-1.1
Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of
- affected < 20260812-1.1fixed 20260812-1.1
Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result ma
- affected < 20260812-1.1fixed 20260812-1.1
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. Thi
- affected < 20260812-1.1fixed 20260812-1.1
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privil
- affected < 20260512-1.1fixed 20260512-1.1
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated
- affected < 20260210-1.1fixed 20260210-1.1
Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially
- affected < 20250812-1.1fixed 20250812-1.1
Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
- affected < 20250812-1.1fixed 20250812-1.1
Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
- affected < 20250812-1.1fixed 20250812-1.1
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
- affected < 20250812-1.1fixed 20250812-1.1
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Xeon(R) 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access
- affected < 20250812-1.1fixed 20250812-1.1
Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
- affected < 20250812-1.1fixed 20250812-1.1
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
- affected < 20250812-1.1fixed 20250812-1.1
Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access.
- affected < 20250512-1.1fixed 20250512-1.1
Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
- affected < 20250512-1.1fixed 20250512-1.1
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Core™ processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access.
- affected < 20250512-1.1fixed 20250512-1.1
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.
Page 1 of 4