Bug 2514115 (CVE-2025-31936) - CVE-2025-31936 kernel: microcode_ctl: Intel Xeon 6 Processors: Privilege escalation via improper memory range handling in SMM
Summary: CVE-2025-31936 kernel: microcode_ctl: Intel Xeon 6 Processors: Privilege esca...
Keywords:
Status: NEW
Alias: CVE-2025-31936
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-11 16:53 UTC by OSIDB Bzimport
Modified: 2026-10-01 15:50 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:65147 0 None None None 2026-09-08 09:22:34 UTC
Red Hat Product Errata RHSA-2026:67979 0 None None None 2026-09-16 12:29:07 UTC
Red Hat Product Errata RHSA-2026:68011 0 None None None 2026-09-16 12:52:58 UTC

Description OSIDB Bzimport 2026-08-11 16:53:17 UTC
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Comment 1 errata-xmlrpc 2026-09-08 09:22:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:65147 https://access.redhat.com/errata/RHSA-2026:65147

Comment 2 Jon Orris 2026-09-16 12:29:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:67979 https://access.redhat.com/errata/RHSA-2026:67979

Comment 3 Jon Orris 2026-09-16 12:52:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:68011 https://access.redhat.com/errata/RHSA-2026:68011


Note You need to log in before you can comment on or make changes to this bug.