{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "Update Intel CPU microcode to 20260812 release, addresses\n  CVE-2025-35973 (INTEL-SA-01428); the release also carries INTEL-SA-01379,\n  -01404, -01423, -01435, -01441, -01442 and -01443. 20260812 withdraws the\n  06-aa-04 revision 0x2a that 20260811 shipped, so MTL C0 (cpuid:A06A4) gets\n  0x28:\n  - Addition of cpuid:806F8/0x10 microcode at revision 0x2c000435;\n  - Addition of cpuid:806F8/0x87 microcode at revision 0x2b000685;\n  - Addition of cpuid:90672/0x07 microcode at revision 0x3e;\n  - Addition of cpuid:906A3/0x80 microcode at revision 0x43b;\n  - Addition of cpuid:B0671/0x36 microcode at revision 0x137;\n  - Addition of cpuid:B0674/0x36 microcode at revision 0x137;\n  - Addition of cpuid:B06A2/0xe0 microcode at revision 0x6134;\n  - Addition of cpuid:C0662/0x82 microcode at revision 0x122;\n  - Addition of cpuid:C06C1/0x94 microcode at revision 0x11c;\n  - Addition of cpuid:C06C2/0x94 microcode at revision 0x11c;\n  - Addition of cpuid:C06C3/0x94 microcode at revision 0x11c;\n  - Addition of cpuid:C06F2/0x87 microcode at revision 0x210002f4;\n  - Addition of cpuid:D0650/0xc0 microcode at revision 0xc;\n  - Addition of cpuid:D0651/0xc0 microcode at revision 0xc;\n  - Addition of cpuid:D0670/0x36 microcode at revision 0x137;\n  - Addition of cpuid:E0652/0x94 microcode at revision 0x11c;\n  - Removal of cpuid:806F8/0x10 microcode at revision 0x2c000410;\n  - Removal of cpuid:806F8/0x87 microcode at revision 0x2b000650;\n  - Removal of cpuid:90672/0x07 microcode at revision 0x3d;\n  - Removal of cpuid:906A3/0x80 microcode at revision 0x43a;\n  - Removal of cpuid:B0671/0x32 microcode at revision 0x132;\n  - Removal of cpuid:B0674/0x32 microcode at revision 0x132;\n  - Removal of cpuid:B06A2/0xe0 microcode at revision 0x6133;\n  - Removal of cpuid:C0662/0x82 microcode at revision 0x11a;\n  - Removal of cpuid:C06F2/0x87 microcode at revision 0x21000291;\n  - Removal of cpuid:C06F2/0x87 microcode at revision 0x210002c0;\n  - Update of cpuid:606A6/0x87 (ICX-SP D0) microcode from revision 0xd000410\n    up to 0xd000433;\n  - Update of cpuid:606C1/0x10 microcode from revision 0x10002e0 up to\n    0x1000301;\n  - Update of cpuid:706E5/0x80 (ICL-U/Y D1) microcode from revision 0xca up to\n    0xce;\n  - Update of cpuid:806C1/0x80 (TGL-UP3/UP4 B1) microcode from revision 0xbc\n    up to 0xbe;\n  - Update of cpuid:806C2/0xc2 (TGL-R C0) microcode from revision 0x3c up to\n    0x3e;\n  - Update of cpuid:806D1/0xc2 (TGL-H R0) microcode from revision 0x56 up to\n    0x58;\n  - Update of cpuid:806F4/0x10 microcode from revision 0x2c000410 up to\n    0x2c000435;\n  - Update of cpuid:806F4/0x87 microcode from revision 0x2b000650 up to\n    0x2b000685;\n  - Update of cpuid:806F5/0x10 microcode from revision 0x2c000410 up to\n    0x2c000435;\n  - Update of cpuid:806F5/0x87 microcode from revision 0x2b000650 up to\n    0x2b000685;\n  - Update of cpuid:806F6/0x10 microcode from revision 0x2c000410 up to\n    0x2c000435;\n  - Update of cpuid:806F6/0x87 microcode from revision 0x2b000650 up to\n    0x2b000685;\n  - Update of cpuid:806F7/0x87 microcode from revision 0x2b000650 up to\n    0x2b000685;\n  - Update of cpuid:90675/0x07 microcode from revision 0x3d up to 0x3e;\n  - Update of cpuid:906A4/0x40 microcode from revision 0xb up to 0xc;\n  - Update of cpuid:906A4/0x80 microcode from revision 0x43a up to 0x43b;\n  - Update of cpuid:A0671/0x02 (RKL-S B0) microcode from revision 0x64 up to\n    0x66;\n  - Update of cpuid:A06A4/0xe6 microcode from revision 0x25 up to 0x28;\n  - Update of cpuid:A06D1/0x20 microcode from revision 0xa000124 up to\n    0xa000151;\n  - Update of cpuid:A06D1/0x95 microcode from revision 0x10003f0 up to\n    0x1000434;\n  - Update of cpuid:A06E1/0x97 microcode from revision 0x1000273 up to\n    0x1000309;\n  - Update of cpuid:A06F3/0x01 microcode from revision 0x3000382 up to\n    0x30003b2;\n  - Update of cpuid:B0650/0x80 microcode from revision 0xa up to 0xe;\n  - Update of cpuid:B06A3/0xe0 microcode from revision 0x6133 up to 0x6134;\n  - Update of cpuid:B06A8/0xe0 microcode from revision 0x6133 up to 0x6134;\n  - Update of cpuid:B06D1/0x80 microcode from revision 0x125 up to 0x128;\n  - Update of cpuid:B06E0/0x19 microcode from revision 0x1e up to 0x21;\n  - Update of cpuid:B06F2/0x07 microcode from revision 0x3d up to 0x3e;\n  - Update of cpuid:B06F5/0x07 microcode from revision 0x3d up to 0x3e;\n  - Update of cpuid:B06F6/0x07 microcode from revision 0x3d up to 0x3e;\n  - Update of cpuid:B06F7/0x07 microcode from revision 0x3d up to 0x3e;\n  - Update of cpuid:C0652/0x82 microcode from revision 0x11a up to 0x122;\n  - Update of cpuid:C0664/0x82 microcode from revision 0x11a up to 0x122;\n  - Update of cpuid:C06A2/0x82 microcode from revision 0x11a up to 0x122;\n  - Update of cpuid:C06F1/0x87 microcode from revision 0x21000291 up to\n    0x210002f4;\n  - Update of cpuid:C06F1/0x87 microcode from revision 0x210002c0 up to\n    0x210002f4;\n- Keep cpuid:50656 (CLX-SP B0) and cpuid:C06F1 (EMR-SP A0) microcode that\n  upstream dropped, as microcode_ctl-4:20260812-1.el8_10 does.",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789117244",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789117244"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/advisories/2026/clsa-2026_1789117244.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-11T09:01:17Z",
      "generator": {
        "date": "2026-09-11T09:01:17Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1789117244",
      "initial_release_date": "2026-09-11T09:01:17Z",
      "revision_history": [
        {
          "date": "2026-09-11T09:01:17Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "microcode_ctl: Fix of CVE-2025-35973"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@20260812-2.el8.tuxcare.els1?arch=x86_64&epoch=4"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@20251111-2.el8.tuxcare.els1?arch=x86_64&epoch=4"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@20250512-2.el8.tuxcare.els1?arch=x86_64&epoch=4"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@20250211-2.el8.tuxcare.els1?arch=x86_64&epoch=4"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@20240910-2.el8.tuxcare.els1?arch=x86_64&epoch=4"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-35973",
      "cwe": {
        "id": "CWE-229",
        "name": "Improper Handling of Values"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-Stream-8:microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64"
        ],
        "known_affected": [
          "CentOS-Stream-8:microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-35973"
        },
        {
          "category": "external",
          "summary": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html",
          "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html"
        }
      ],
      "release_date": "2026-08-11T17:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-11T09:00:46.519921Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789117244",
          "product_ids": [
            "CentOS-Stream-8:microcode_ctl-4:20260812-2.el8.tuxcare.els1.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789117244"
        },
        {
          "category": "none_available",
          "date": "2026-08-11T17:17:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-Stream-8:microcode_ctl-4:20240910-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:microcode_ctl-4:20250211-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:microcode_ctl-4:20250512-2.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:microcode_ctl-4:20251111-2.el8.tuxcare.els1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}