#1144158 intel-microcode: CVE-2026-20707 CVE-2026-20901 CVE-2026-20713 CVE-2026-20760 CVE-2026-20716 CVE-2025-35973 CVE-2026-20917 CVE-2025-31938 CVE-2025-31936

Package:
src:intel-microcode
Source:
src:intel-microcode
Submitter:
Salvatore Bonaccorso
Date:
2026-08-13 06:21:01 UTC
Severity:
normal
Tags:
#1144158#5
Date:
2026-08-11 18:54:53 UTC
From:
To:
Hi,

The following vulnerabilities were published for intel-microcode.

CVE-2026-20707[0]:
| Hardware logic contains race conditions for some 3rd Gen Intel(R)
| Xeon(R) Scalable Processors within Ring 3: unprivileged software may
| allow a denial of service. Unprivileged software adversary with an
| authenticated user combined with a high complexity attack may enable
| denial of service. This result may potentially occur via local
| access when attack requirements are not present with special
| internal knowledge and requires no user interaction. The potential
| vulnerability may impact the confidentiality (none), integrity
| (none) and availability (high) of the vulnerable system, resulting
| in subsequent system confidentiality (none), integrity (none) and
| availability (high) impacts.


CVE-2026-20901[1]:
| Improper input validation for some Intel(R) Xeon(R) processors
| within firmware may allow an escalation of privilege. Startup code
| and smm adversary with a privileged user combined with a high
| complexity attack may enable data alteration. This result may
| potentially occur via local access when attack requirements are
| present without special internal knowledge and requires no user
| interaction. The potential vulnerability may impact the
| confidentiality (none), integrity (none) and availability (none) of
| the vulnerable system, resulting in subsequent system
| confidentiality (none), integrity (high) and availability (none)
| impacts.


CVE-2026-20713[2]:
| Always-incorrect control flow implementation in some firmware for
| some Intel(R) Xeon(R) processors may allow an escalation of
| privilege. System software adversary with a privileged user combined
| with a high complexity attack may enable escalation of privilege.
| This result may potentially occur via local access when attack
| requirements are not present without special internal knowledge and
| requires no user interaction. The potential vulnerability may impact
| the confidentiality (none), integrity (none) and availability (none)
| of the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (high) and availability (none)
| impacts.


CVE-2026-20760[3]:
| Improper handling of overlap between protected memory ranges in some
| microcode for some Intel(R) Processors within Ring 0: Hypervisor may
| allow an escalation of privilege. Authorized adversary with a
| privileged user combined with a low complexity attack may enable
| escalation of privilege. This result may potentially occur via local
| access when attack requirements are not present without special
| internal knowledge and requires no user interaction. The potential
| vulnerability may impact the confidentiality (high), integrity
| (high) and availability (high) of the vulnerable system, resulting
| in subsequent system confidentiality (none), integrity (none) and
| availability (none) impacts.


CVE-2026-20716[4]:
| Improper access control for some Intel(R) Processors within Ring 3:
| User Applications may allow an escalation of privilege. Simple
| hardware adversary with an authenticated user combined with a high
| complexity attack may enable escalation of privilege. This result
| may potentially occur via local access when attack requirements are
| present with special internal knowledge and requires no user
| interaction. The potential vulnerability may impact the
| confidentiality (high), integrity (high) and availability (none) of
| the vulnerable system, resulting in subsequent system
| confidentiality (none), integrity (none) and availability (none)
| impacts.


CVE-2025-35973[5]:
| Improper handling of values for some Intel(R) Processors within Ring
| 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of
| privilege. Authorized adversary with a privileged user combined with
| a high complexity attack may enable escalation of privilege. This
| result may potentially occur via local access when attack
| requirements are present with special internal knowledge and require
| no user interaction. The potential vulnerability may impact the
| confidentiality (low), integrity (low) and availability (none) of
| the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (high) and availability (none)
| impacts.


CVE-2026-20917[6]:
| Exposure of sensitive information caused by incorrect data
| forwarding during transient execution for some Intel(R) Processors
| within Ring 0: Hypervisor and Kernel may allow information
| disclosure. System software adversary with a privileged user
| combined with a high complexity attack may enable data exposure.
| This result may potentially occur via local access when attack
| requirements are not present without special internal knowledge and
| requires no user interaction. The potential vulnerability may impact
| the confidentiality (none), integrity (none) and availability (none)
| of the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (none) and availability (none)
| impacts.


CVE-2025-31938[7]:
| Insufficient granularity of access control in some subsystem for
| some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may
| allow an information disclosure. Authorized adversary with an
| authenticated user combined with a high complexity attack may enable
| data exposure. This result may potentially occur via local access
| when attack requirements are present with special internal knowledge
| and requires no user interaction. The potential vulnerability may
| impact the confidentiality (none), integrity (none) and availability
| (none) of the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (none) and availability (none)
| impacts.


CVE-2025-31936[8]:
| Improper handling of overlap between protected memory ranges for
| some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within
| SMM may allow an escalation of privilege. SMM adversary with a
| privileged user combined with a high complexity attack may enable
| escalation of privilege. This result may potentially occur via local
| access when attack requirements are present with special internal
| knowledge and requires no user interaction. The potential
| vulnerability may impact the confidentiality (high), integrity
| (high) and availability (none) of the vulnerable system, resulting
| in subsequent system confidentiality (none), integrity (none) and
| availability (none) impacts.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-20707
https://www.cve.org/CVERecord?id=CVE-2026-20707
[1] https://security-tracker.debian.org/tracker/CVE-2026-20901
https://www.cve.org/CVERecord?id=CVE-2026-20901
[2] https://security-tracker.debian.org/tracker/CVE-2026-20713
https://www.cve.org/CVERecord?id=CVE-2026-20713
[3] https://security-tracker.debian.org/tracker/CVE-2026-20760
https://www.cve.org/CVERecord?id=CVE-2026-20760
[4] https://security-tracker.debian.org/tracker/CVE-2026-20716
https://www.cve.org/CVERecord?id=CVE-2026-20716
[5] https://security-tracker.debian.org/tracker/CVE-2025-35973
https://www.cve.org/CVERecord?id=CVE-2025-35973
[6] https://security-tracker.debian.org/tracker/CVE-2026-20917
https://www.cve.org/CVERecord?id=CVE-2026-20917
[7] https://security-tracker.debian.org/tracker/CVE-2025-31938
https://www.cve.org/CVERecord?id=CVE-2025-31938
[8] https://security-tracker.debian.org/tracker/CVE-2025-31936
https://www.cve.org/CVERecord?id=CVE-2025-31936
[9] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144158#10
Date:
2026-08-13 06:18:48 UTC
From:
To:
Hi,

FTR, there was
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812
with dropping MTL/06-aa-04/c0 due to functional issues.

Regards,
Salvatore