CVE-2025-35973
Description
A flaw was found in Intel(R) Processors within Ring 0, affecting the kernel, hypervisor, and bare metal operating systems. Improper handling of values may allow an authorized adversary with privileged user access to perform a local, high-complexity attack. This can lead to an escalation of privilege, potentially resulting in high impact to the confidentiality and integrity of the system.
Statement
Red Hat is aware of a hardware vulnerability affecting some Intel processors that could allow a local attacker who already has privileged access to escalate privileges by exploiting improper handling of internal processor values during Ring 0 execution. In the most severe case, this could allow a privileged workload running inside a virtual machine to escalate access into the underlying hypervisor. Exploitation requires local access, existing privileged access, and a high degree of attack complexity, including detailed knowledge of the processor's internal behavior.
Red Hat products that provide workload isolation using a hypervisor, such as Red Hat OpenShift sandboxed containers (which uses Kata Containers), are assessed as Important severity because of the potential impact on isolation between different tenants' workloads if the underlying processor is vulnerable and has not been updated.
Mitigation
This is a hardware-level vulnerability in the affected Intel processors. There is no code-level fix available in Red Hat OpenShift sandboxed containers or other affected Red Hat components; the issue must be addressed at the processor firmware layer.
Red Hat recommends that customers apply the latest CPU microcode or system firmware update from their hardware manufacturer. Intel has released microcode updates addressing this issue; see Intel Security Advisory INTEL-SA-01428 (https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html) for affected processor families and update guidance.
Intel has indicated that a further Trusted Computing Base (TCB) recovery is planned for this issue. Red Hat will update this guidance if additional remediation steps become necessary once that information is available.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.2 | N/A | N/A |
| Attack Vector | Local | N/A | N/A |
| Attack Complexity | High | N/A | N/A |
| Privileges Required | High | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Changed | N/A | N/A |
| Confidentiality | High | N/A | N/A |
| Integrity Impact | High | N/A | N/A |
| Availability Impact | None | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.