{"id":"SUSE-SU-2026:3124-1","summary":"Security update for microcode_ctl","details":"This update for microcode_ctl fixes the following issue:\n\n- CVE-2025-35979: shared microarchitectural predictor state in VMX non-root operation could lead to data leaks\n  (bsc#1265189).\n\nChanges for microcode_ctl:\n\n- Intel CPU Microcode was updated to the 20260512 release (bsc#1265189):\n\n * Update for various functional issues.\n ### New Platforms\n | Processor | Stepping | F-M-S/PI | Old Ver | New Ver | Products\n |:---------------|:---------|:------------|:---------|:---------|:---------\n | PTL 404 | A1 | 06-cc-03/90 | | 0000011b | Intel Core Ultra Processor (Series 3)\n | PTL-H 484/12Xe | A0/B0 | 06-cc-02/90 | | 0000011b | Intel Core Ultra Processor (Series 3)\n ### Updated Platforms\n | ARL-H | A1 | 06-c5-02/82 | 0000011b | 00000121 | Core Ultra Processor (Series 2)\n | ARL-S/HX (8P) | B0 | 06-c6-02/82 | 0000011b | 00000121 | Core Ultra Processor (Series 2)\n | EMR-SP | A1 | 06-cf-02/87 | 210002d3 | 210002e0 | Xeon Scalable Gen5\n | GNR-AP/SP | Bx/Hx/Lx | 06-ad-01/95 | 01000405 | 01000423 | Xeon 6900/6700/6500 Series Processors with P-Cores\n | GNR-D | B0/B1 | 06-ae-01/97 | 01000303 | 01000307 | Xeon 6700P-B/6500P-B Series SoC with P-Cores\n | GNR-SP R1S | Bx/Hx/Lx | 06-ad-01/20 | 0a000133 | 0a000142 | Xeon 6700/6500-Series Processors with P-Cores\n | LNL | B0 | 06-bd-01/80 | 00000125 | 00000126 | Core Ultra 200 V Series Processor\n | SPR-SP | E4/S2 | 06-8f-07/87 | 2b000661 | 2b000670 | Xeon Scalable Gen4\n | SPR-SP | E5/S3 | 06-8f-08/87 | 2b000661 | 2b000670 | Xeon Scalable Gen4\n | SRF-AP/SP | C0 | 06-af-03/01 | 03000382 | 030003a3 | Xeon 6900/6700-Series Processors with E-Cores\n  \n- Intel CPU Microcode was updated to the 20260227 release:\n\n * Update for functional issues. Refer to Intel Xeon\n 6700P-B/6500P-B-Series SoC with P-Cores for details.\n * ### Updated Platforms\n * | GNR-D | B0/B1 | 06-ae-01/97 | 010002f3 |\n 01000303 | Xeon 6700P-B/6500P-B Series SoC with P-Cores\n","modified":"2026-07-21T09:45:06.783347392Z","published":"2026-07-20T07:01:24Z","related":["CVE-2025-35979"],"upstream":["CVE-2025-35979"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263124-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265189"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-35979"}],"affected":[{"package":{"name":"microcode_ctl","ecosystem":"SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE","purl":"pkg:rpm/suse/microcode_ctl&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4%20LTSS%20EXTREME%20CORE"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.17-102.83.95.1"}]}],"ecosystem_specific":{"binaries":[{"microcode_ctl":"1.17-102.83.95.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3124-1.json"}}],"schema_version":"1.7.5"}