#1144158 intel-microcode: CVE-2026-20707 CVE-2026-20901 CVE-2026-20713 CVE-2026-20760 CVE-2026-20716 CVE-2025-35973 CVE-2026-20917 CVE-2025-31938 CVE-2025-31936

Package:
src:intel-microcode
Source:
src:intel-microcode
Submitter:
Salvatore Bonaccorso
Date:
2026-08-25 12:33:01 UTC
Severity:
normal
Tags:
#1144158#5
Date:
2026-08-11 18:54:53 UTC
From:
To:
Hi,

The following vulnerabilities were published for intel-microcode.

CVE-2026-20707[0]:
| Hardware logic contains race conditions for some 3rd Gen Intel(R)
| Xeon(R) Scalable Processors within Ring 3: unprivileged software may
| allow a denial of service. Unprivileged software adversary with an
| authenticated user combined with a high complexity attack may enable
| denial of service. This result may potentially occur via local
| access when attack requirements are not present with special
| internal knowledge and requires no user interaction. The potential
| vulnerability may impact the confidentiality (none), integrity
| (none) and availability (high) of the vulnerable system, resulting
| in subsequent system confidentiality (none), integrity (none) and
| availability (high) impacts.


CVE-2026-20901[1]:
| Improper input validation for some Intel(R) Xeon(R) processors
| within firmware may allow an escalation of privilege. Startup code
| and smm adversary with a privileged user combined with a high
| complexity attack may enable data alteration. This result may
| potentially occur via local access when attack requirements are
| present without special internal knowledge and requires no user
| interaction. The potential vulnerability may impact the
| confidentiality (none), integrity (none) and availability (none) of
| the vulnerable system, resulting in subsequent system
| confidentiality (none), integrity (high) and availability (none)
| impacts.


CVE-2026-20713[2]:
| Always-incorrect control flow implementation in some firmware for
| some Intel(R) Xeon(R) processors may allow an escalation of
| privilege. System software adversary with a privileged user combined
| with a high complexity attack may enable escalation of privilege.
| This result may potentially occur via local access when attack
| requirements are not present without special internal knowledge and
| requires no user interaction. The potential vulnerability may impact
| the confidentiality (none), integrity (none) and availability (none)
| of the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (high) and availability (none)
| impacts.


CVE-2026-20760[3]:
| Improper handling of overlap between protected memory ranges in some
| microcode for some Intel(R) Processors within Ring 0: Hypervisor may
| allow an escalation of privilege. Authorized adversary with a
| privileged user combined with a low complexity attack may enable
| escalation of privilege. This result may potentially occur via local
| access when attack requirements are not present without special
| internal knowledge and requires no user interaction. The potential
| vulnerability may impact the confidentiality (high), integrity
| (high) and availability (high) of the vulnerable system, resulting
| in subsequent system confidentiality (none), integrity (none) and
| availability (none) impacts.


CVE-2026-20716[4]:
| Improper access control for some Intel(R) Processors within Ring 3:
| User Applications may allow an escalation of privilege. Simple
| hardware adversary with an authenticated user combined with a high
| complexity attack may enable escalation of privilege. This result
| may potentially occur via local access when attack requirements are
| present with special internal knowledge and requires no user
| interaction. The potential vulnerability may impact the
| confidentiality (high), integrity (high) and availability (none) of
| the vulnerable system, resulting in subsequent system
| confidentiality (none), integrity (none) and availability (none)
| impacts.


CVE-2025-35973[5]:
| Improper handling of values for some Intel(R) Processors within Ring
| 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of
| privilege. Authorized adversary with a privileged user combined with
| a high complexity attack may enable escalation of privilege. This
| result may potentially occur via local access when attack
| requirements are present with special internal knowledge and require
| no user interaction. The potential vulnerability may impact the
| confidentiality (low), integrity (low) and availability (none) of
| the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (high) and availability (none)
| impacts.


CVE-2026-20917[6]:
| Exposure of sensitive information caused by incorrect data
| forwarding during transient execution for some Intel(R) Processors
| within Ring 0: Hypervisor and Kernel may allow information
| disclosure. System software adversary with a privileged user
| combined with a high complexity attack may enable data exposure.
| This result may potentially occur via local access when attack
| requirements are not present without special internal knowledge and
| requires no user interaction. The potential vulnerability may impact
| the confidentiality (none), integrity (none) and availability (none)
| of the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (none) and availability (none)
| impacts.


CVE-2025-31938[7]:
| Insufficient granularity of access control in some subsystem for
| some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may
| allow an information disclosure. Authorized adversary with an
| authenticated user combined with a high complexity attack may enable
| data exposure. This result may potentially occur via local access
| when attack requirements are present with special internal knowledge
| and requires no user interaction. The potential vulnerability may
| impact the confidentiality (none), integrity (none) and availability
| (none) of the vulnerable system, resulting in subsequent system
| confidentiality (high), integrity (none) and availability (none)
| impacts.


CVE-2025-31936[8]:
| Improper handling of overlap between protected memory ranges for
| some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within
| SMM may allow an escalation of privilege. SMM adversary with a
| privileged user combined with a high complexity attack may enable
| escalation of privilege. This result may potentially occur via local
| access when attack requirements are present with special internal
| knowledge and requires no user interaction. The potential
| vulnerability may impact the confidentiality (high), integrity
| (high) and availability (none) of the vulnerable system, resulting
| in subsequent system confidentiality (none), integrity (none) and
| availability (none) impacts.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-20707
https://www.cve.org/CVERecord?id=CVE-2026-20707
[1] https://security-tracker.debian.org/tracker/CVE-2026-20901
https://www.cve.org/CVERecord?id=CVE-2026-20901
[2] https://security-tracker.debian.org/tracker/CVE-2026-20713
https://www.cve.org/CVERecord?id=CVE-2026-20713
[3] https://security-tracker.debian.org/tracker/CVE-2026-20760
https://www.cve.org/CVERecord?id=CVE-2026-20760
[4] https://security-tracker.debian.org/tracker/CVE-2026-20716
https://www.cve.org/CVERecord?id=CVE-2026-20716
[5] https://security-tracker.debian.org/tracker/CVE-2025-35973
https://www.cve.org/CVERecord?id=CVE-2025-35973
[6] https://security-tracker.debian.org/tracker/CVE-2026-20917
https://www.cve.org/CVERecord?id=CVE-2026-20917
[7] https://security-tracker.debian.org/tracker/CVE-2025-31938
https://www.cve.org/CVERecord?id=CVE-2025-31938
[8] https://security-tracker.debian.org/tracker/CVE-2025-31936
https://www.cve.org/CVERecord?id=CVE-2025-31936
[9] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144158#10
Date:
2026-08-13 06:18:48 UTC
From:
To:
Hi,

FTR, there was
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812
with dropping MTL/06-aa-04/c0 due to functional issues.

Regards,
Salvatore

#1144158#15
Date:
2026-08-25 12:15:26 UTC
From:
To:
Hello,

I am holding off on this update because it has caused severe regressions, and more issues are still being found with it.

The most immediate regression was reported very quickly by users, and was reverted next-day by Intel (release 20260812), but there are other updates still in 20260812 that cause boot hangs on Xeon servers with older microcode/firmware, for example.

I.e. it is the dreaded "update incompatible with older system firmware" problem showing it face once again.

The current recommendation is: update your system firmware, push your vendor for them to properly issue firmware updates if need be.

#1144158#20
Date:
2026-08-25 12:30:11 UTC
From:
To:
Hi Henrique,

Thanks for this update!

Regards,
Salvatore