{"id":"MGASA-2025-0236","summary":"Updated microcode packages fix security vulnerabilities","details":"The updated package updates AMD cpu microcode for processor family 19h,\nadds AMD cpu microcode for processor family 1ah and fixes security\nvulnerabilities for Intel processors:\nImproper Isolation or Compartmentalization in the stream cache mechanism\nfor some Intel® Processors may allow an authenticated user to\npotentially enable escalation of privilege via local access.\n(CVE-2025-20109)\nSequence of processor instructions leads to unexpected behavior for some\nIntel® Xeon® 6 Scalable processors may allow an authenticated user to\npotentially enable escalation of privilege via local access.\n(CVE-2025-22840)\nInsufficient granularity of access control in the OOB-MSM for some\nIntel® Xeon® 6 Scalable processors may allow a privileged user to\npotentially enable escalation of privilege via adjacent access.\n(CVE-2025-22839)\nImproper handling of overlap between protected memory ranges for some\nIntel® Xeon® 6 processor with Intel® TDX may allow a privileged user to\npotentially enable escalation of privilege via local access.\n(CVE-2025-22889)\nImproper buffer restrictions for some Intel® Xeon® Processor firmware\nwith SGX enabled may allow a privileged user to potentially enable\nescalation of privilege via local access. (CVE-2025-20053)\nInsufficient control flow management in the Alias Checking Trusted\nModule (ACTM) firmware for some Intel® Xeon® processors may allow a\nprivileged user to potentially enable escalation of privilege via local\naccess. (CVE-2025-24305)\nMissing reference to active allocated resource for some Intel® Xeon®\nprocessors may allow an authenticated user to potentially enable denial\nof service via local access. (CVE-2025-21090)\nOut-of-bounds write in the memory subsystem for some Intel® Xeon® 6\nprocessors when using Intel® SGX or Intel® TDX may allow a privileged\nuser to potentially enable escalation of privilege via local access.\n(CVE-2025-26403)\nImproperly implemented security check for standard in the DDRIO\nconfiguration for some Intel® Xeon® 6 Processors when using Intel® SGX\nor Intel® TDX may allow a privileged user to potentially enable\nescalation of privilege via local access. (CVE-2025-32086)\n","modified":"2026-04-16T04:43:12.498564606Z","published":"2025-10-10T03:12:21Z","upstream":["CVE-2025-20053","CVE-2025-20109","CVE-2025-21090","CVE-2025-22839","CVE-2025-22840","CVE-2025-22889","CVE-2025-24305","CVE-2025-26403","CVE-2025-32086"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0236.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34629"},{"type":"WEB","url":"https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20250812"}],"affected":[{"package":{"name":"microcode","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/microcode?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.20250812-1.mga9.nonfree"}]}],"ecosystem_specific":{"section":"nonfree"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0236.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}