Source: intel-microcode Version: 3.20260227.1 Severity: important Tags: security upstream trixie forky sid X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for intel-microcode. CVE-2026-20707[0]: | Hardware logic contains race conditions for some 3rd Gen Intel(R) | Xeon(R) Scalable Processors within Ring 3: unprivileged software may | allow a denial of service. Unprivileged software adversary with an | authenticated user combined with a high complexity attack may enable | denial of service. This result may potentially occur via local | access when attack requirements are not present with special | internal knowledge and requires no user interaction. The potential | vulnerability may impact the confidentiality (none), integrity | (none) and availability (high) of the vulnerable system, resulting | in subsequent system confidentiality (none), integrity (none) and | availability (high) impacts. CVE-2026-20901[1]: | Improper input validation for some Intel(R) Xeon(R) processors | within firmware may allow an escalation of privilege. Startup code | and smm adversary with a privileged user combined with a high | complexity attack may enable data alteration. This result may | potentially occur via local access when attack requirements are | present without special internal knowledge and requires no user | interaction. The potential vulnerability may impact the | confidentiality (none), integrity (none) and availability (none) of | the vulnerable system, resulting in subsequent system | confidentiality (none), integrity (high) and availability (none) | impacts. CVE-2026-20713[2]: | Always-incorrect control flow implementation in some firmware for | some Intel(R) Xeon(R) processors may allow an escalation of | privilege. System software adversary with a privileged user combined | with a high complexity attack may enable escalation of privilege. | This result may potentially occur via local access when attack | requirements are not present without special internal knowledge and | requires no user interaction. The potential vulnerability may impact | the confidentiality (none), integrity (none) and availability (none) | of the vulnerable system, resulting in subsequent system | confidentiality (high), integrity (high) and availability (none) | impacts. CVE-2026-20760[3]: | Improper handling of overlap between protected memory ranges in some | microcode for some Intel(R) Processors within Ring 0: Hypervisor may | allow an escalation of privilege. Authorized adversary with a | privileged user combined with a low complexity attack may enable | escalation of privilege. This result may potentially occur via local | access when attack requirements are not present without special | internal knowledge and requires no user interaction. The potential | vulnerability may impact the confidentiality (high), integrity | (high) and availability (high) of the vulnerable system, resulting | in subsequent system confidentiality (none), integrity (none) and | availability (none) impacts. CVE-2026-20716[4]: | Improper access control for some Intel(R) Processors within Ring 3: | User Applications may allow an escalation of privilege. Simple | hardware adversary with an authenticated user combined with a high | complexity attack may enable escalation of privilege. This result | may potentially occur via local access when attack requirements are | present with special internal knowledge and requires no user | interaction. The potential vulnerability may impact the | confidentiality (high), integrity (high) and availability (none) of | the vulnerable system, resulting in subsequent system | confidentiality (none), integrity (none) and availability (none) | impacts. CVE-2025-35973[5]: | Improper handling of values for some Intel(R) Processors within Ring | 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of | privilege. Authorized adversary with a privileged user combined with | a high complexity attack may enable escalation of privilege. This | result may potentially occur via local access when attack | requirements are present with special internal knowledge and require | no user interaction. The potential vulnerability may impact the | confidentiality (low), integrity (low) and availability (none) of | the vulnerable system, resulting in subsequent system | confidentiality (high), integrity (high) and availability (none) | impacts. CVE-2026-20917[6]: | Exposure of sensitive information caused by incorrect data | forwarding during transient execution for some Intel(R) Processors | within Ring 0: Hypervisor and Kernel may allow information | disclosure. System software adversary with a privileged user | combined with a high complexity attack may enable data exposure. | This result may potentially occur via local access when attack | requirements are not present without special internal knowledge and | requires no user interaction. The potential vulnerability may impact | the confidentiality (none), integrity (none) and availability (none) | of the vulnerable system, resulting in subsequent system | confidentiality (high), integrity (none) and availability (none) | impacts. CVE-2025-31938[7]: | Insufficient granularity of access control in some subsystem for | some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may | allow an information disclosure. Authorized adversary with an | authenticated user combined with a high complexity attack may enable | data exposure. This result may potentially occur via local access | when attack requirements are present with special internal knowledge | and requires no user interaction. The potential vulnerability may | impact the confidentiality (none), integrity (none) and availability | (none) of the vulnerable system, resulting in subsequent system | confidentiality (high), integrity (none) and availability (none) | impacts. CVE-2025-31936[8]: | Improper handling of overlap between protected memory ranges for | some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within | SMM may allow an escalation of privilege. SMM adversary with a | privileged user combined with a high complexity attack may enable | escalation of privilege. This result may potentially occur via local | access when attack requirements are present with special internal | knowledge and requires no user interaction. The potential | vulnerability may impact the confidentiality (high), integrity | (high) and availability (none) of the vulnerable system, resulting | in subsequent system confidentiality (none), integrity (none) and | availability (none) impacts. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-20707 https://www.cve.org/CVERecord?id=CVE-2026-20707 [1] https://security-tracker.debian.org/tracker/CVE-2026-20901 https://www.cve.org/CVERecord?id=CVE-2026-20901 [2] https://security-tracker.debian.org/tracker/CVE-2026-20713 https://www.cve.org/CVERecord?id=CVE-2026-20713 [3] https://security-tracker.debian.org/tracker/CVE-2026-20760 https://www.cve.org/CVERecord?id=CVE-2026-20760 [4] https://security-tracker.debian.org/tracker/CVE-2026-20716 https://www.cve.org/CVERecord?id=CVE-2026-20716 [5] https://security-tracker.debian.org/tracker/CVE-2025-35973 https://www.cve.org/CVERecord?id=CVE-2025-35973 [6] https://security-tracker.debian.org/tracker/CVE-2026-20917 https://www.cve.org/CVERecord?id=CVE-2026-20917 [7] https://security-tracker.debian.org/tracker/CVE-2025-31938 https://www.cve.org/CVERecord?id=CVE-2025-31938 [8] https://security-tracker.debian.org/tracker/CVE-2025-31936 https://www.cve.org/CVERecord?id=CVE-2025-31936 [9] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

