microcode_ctl-20250211-1.el9_6

エラータID: AXSA:2025-10063:04

Release date: 
Friday, June 27, 2025 - 17:09
Subject: 
microcode_ctl-20250211-1.el9_6
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The microcode_ctl packages provide microcode updates for Intel and AMD processors.

Security Fix(es):

* microcode_ctl: Improper input validation in UEFI firmware (CVE-2024-28047)
* microcode_ctl: Insufficient granularity of access control in UEFI firmware (CVE-2024-39279)
* microcode_ctl: mproper initialization in UEFI firmware OutOfBandXML module (CVE-2024-31157)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9 Release Notes linked from the References section.

CVE-2024-28047
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
CVE-2024-31157
Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
CVE-2024-39279
Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. microcode_ctl-20250211-1.el9_6.src.rpm
    MD5: 07759e7ce3510565dc97faab1ab06100
    SHA-256: 250932dabcfb27dc56b3622e2df462f3ae8311c356bb2981d07813da73933373
    Size: 16.92 MB

Asianux Server 9 for x86_64
  1. microcode_ctl-20250211-1.el9_6.noarch.rpm
    MD5: 316ae86ce74b2101ede71cdf46632313
    SHA-256: 9474e62a3067e4bbf4fc29e416b1f9440492ffe825f3b3e598fcf96a67f201a3
    Size: 10.08 MB