[Apollo] Advisories Statistics light light Login

RLSA-2026:68011

Security Mirrored from RHSA-2026:68011
Issued at: 2026-09-17
Updated at: 2026-09-17

Advisory content derived from Red Hat RHSA-2026:68011, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: microcode_ctl security, bug fix, and enhancement update



Description

The microcode_ctl packages provide microcode updates for Intel and AMD processors.

Security Fix(es):

* kernel: hypervisor: Intel Processors: Privilege escalation in Ring 0 via improper value handling (CVE-2025-35973)

* kernel: microcode_ctl: Intel Xeon 6 Processors: Privilege escalation via improper memory range handling in SMM (CVE-2025-31936)

Bug Fix(es) and Enhancement(s):

* [Rocky Linux 9.8.z] Update Intel CPU microcode to the latest version (JIRA:Rocky Linux-260496)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x

Fixes

2514104 2514115

CVEs

CVE-2025-31936 CVE-2025-35973

Affected packages

Rocky Linux 9 aarch64 - BaseOS

microcode_ctl-4:20260210-1.20260812.1.el9_8.src.rpm

Rocky Linux 9 s390x - BaseOS

microcode_ctl-4:20260210-1.20260812.1.el9_8.src.rpm

Rocky Linux 9 ppc64le - BaseOS

microcode_ctl-4:20260210-1.20260812.1.el9_8.src.rpm