Improper Handling of Values Affecting ucode-intel package, versions <20260210-150200.62.1


Severity

Recommended
medium

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.01% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES155-UCODEINTEL-15364474
  • published28 Feb 2026
  • disclosed26 Feb 2026

Introduced: 26 Feb 2026

NewCVE-2025-31648  (opens in a new tab)
CWE-229  (opens in a new tab)

How to fix?

Upgrade SLES:15.5 ucode-intel to version 20260210-150200.62.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ucode-intel package and not the ucode-intel package as distributed by SLES. See How to fix? for SLES:15.5 relevant fixed versions and status.

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

CVSS Base Scores

version 3.1