INFSA-2025:10991: microcode_ctl security update
Information about definition
Identificator: INFSA-2025:10991
Type: security
Release date: 2025-07-17 21:56:10 UTC
Information about package
The microcode_ctl packages provide microcode updates for Intel and AMD processors.
Vulnerabilities description
- CVE-2024-28956
New Spectre-v2 attack classes have been discovered within CPU architectures that enable self-training exploitation of speculative execution within the same privilege domain. These novel techniques bypass existing hardware and software mitigations, including IBPB, eIBRS, and BHI_NO, by leveraging in-kernel gadgets (potentially accessible via SECCOMP/cBPF), Branch Target Buffer (BTB) aliasing, and direct-to-indirect branch predictor training. While the root cause lies in CPU architectural behavior, the vulnerability manifests through kernel-level speculation paths, allowing attackers to potentially leak sensitive memory.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-28956
|
no information | 5.6 | no information |
Updated packages