CVE-2025-35973

Description

A flaw was found in Intel(R) Processors within Ring 0, affecting the kernel, hypervisor, and bare metal operating systems. Improper handling of values may allow an authorized adversary with privileged user access to perform a local, high-complexity attack. This can lead to an escalation of privilege, potentially resulting in high impact to the confidentiality and integrity of the system.

Statement

Red Hat is aware of a hardware vulnerability affecting some Intel processors that could allow a local attacker who already has privileged access to escalate privileges by exploiting improper handling of internal processor values during Ring 0 execution. In the most severe case, this could allow a privileged workload running inside a virtual machine to escalate access into the underlying hypervisor. Exploitation requires local access, existing privileged access, and a high degree of attack complexity, including detailed knowledge of the processor's internal behavior.

Red Hat products that provide workload isolation using a hypervisor, such as Red Hat OpenShift sandboxed containers (which uses Kata Containers), are assessed as Important severity because of the potential impact on isolation between different tenants' workloads if the underlying processor is vulnerable and has not been updated.

Mitigation

This is a hardware-level vulnerability in the affected Intel processors. There is no code-level fix available in Red Hat OpenShift sandboxed containers or other affected Red Hat components; the issue must be addressed at the processor firmware layer.

Red Hat recommends that customers apply the latest CPU microcode or system firmware update from their hardware manufacturer. Intel has released microcode updates addressing this issue; see Intel Security Advisory INTEL-SA-01428 (https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html) for affected processor families and update guidance.

Intel has indicated that a further Trusted Computing Base (TCB) recovery is planned for this issue. Red Hat will update this guidance if additional remediation steps become necessary once that information is available.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.2N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityHighN/AN/A
Privileges RequiredHighN/AN/A
User InteractionNoneN/AN/A
ScopeChangedN/AN/A
ConfidentialityHighN/AN/A
Integrity ImpactHighN/AN/A
Availability ImpactNoneN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.