Lucene search

K
rockyRockylinux Product ErrataRLEA-2023:3843
HistoryJul 08, 2023 - 2:53 a.m.

microcode_ctl bug fix and enhancement update

2023-07-0802:53:40
Rockylinux Product Errata
errata.rockylinux.org
17
update
microcode
rocky linux 8
intel processors
cve-2022-21216
cve-2022-33196
cve-2022-33972
cve-2022-38090
bug fix
enhancement
bz#2171233
bz#2171258

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L

EPSS

0

Percentile

13.2%

An update is available for microcode_ctl.
This update affects Rocky Linux 8.
A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
The microcode_ctl packages provide microcode updates for Intel processors.

Bug Fix(es) and Enhancement(s):

  • Update Intel CPU microcode to microcode-20230214 release, which addresses CVE-2022-21216, CVE-2022-33196, CVE-2022-33972, and CVE-2022-38090. (BZ#2171233, BZ#2171258)
OSVersionArchitecturePackageVersionFilename
rocky8x86_64microcode_ctl< 20220809-2.20230214.1.el8_8microcode_ctl-4:20220809-2.20230214.1.el8_8.x86_64.rpm

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L

EPSS

0

Percentile

13.2%