TGViewer
Qubes OS Qubes OS @qubesos · 1.37K subscribers
Post #1203 122
QSB-117: Intel CPU firmware vulnerabilities
https://www.qubes-os.org/news/2026/08/28/qsb-117/

We have published Qubes Security Bulletin (QSB) 117: Intel CPU firmware vulnerabilities (https://github.com/QubesOS/qubes-secpack/blob/2fae4b5eb43fae0b3bd58cc50444aac283d702fb/QSBs/qsb-117-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.

Qubes Security Bulletin 117


---===[ Qubes Security Bulletin 117 ]===---

2026-08-28

Intel CPU firmware vulnerabilities

User action
------------

Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.

Summary
--------

On 2026-08-11, Intel published "microcode-20260811 Release," [3] which
is associated with several Intel security advisories. Among these
security advisories, we suspect the following may apply to Qubes OS:

- "2026.3 IPU, Intel Processor Load Value Injection Zero Data Advisory"
(INTEL-SA-01423) [4]
- "Intel Processor Firmware Advisory - 01428" (INTEL-SA-01428) [5]
- "Intel Processor Firmware Advisory - 01435" (INTEL-SA-01435) [6]
- "2026.3 IPU, Intel Processor Firmware Advisory" (INTEL-SA-01441) [7]
- "2026.3 IPU, Intel Xeon Processor Firmware Advisory"
(INTEL-SA-01442) [8]

Unfortunately, these advisories do not provide sufficient information
for us to make a definitive assessment about the extent to which these
vulnerabilities affect the security of Qubes OS. Based on the limited
information available, we cannot exclude possibility of a cross-qube
attack.

Impact
-------

On affected systems, an attacker who has managed to compromise one qube
can attempt to exploit these vulnerabilities in order to infer data
belonging to other qubes or escalate their privileges.

Affected systems
-----------------

Only systems with one of the following Intel CPUs are affected by at
least some of the advisories:

- 10th Generation Intel Core
- 11th Generation Intel Core
- Intel Core Ultra, Series 1 to 3
- various Xeon variants

For a more detailed list of affected products see Intel's advisories.

Note: As of this writing, Intel has withdrawn the relevant update for
Meteor Lake (Intel Core Ultra Series 2) CPUs "due to functional issues"
[9]. Due to limited information, the impact of the vulnerabilities
discussed in this bulletin on systems without the relevant update is
unclear.

Patching
---------

The following package contains the security update that addresses the
vulnerability described in this bulletin:

For Qubes 4.3, in dom0:
- microcode_ctl version 2.1.20260812

Note: This package has already finished migrating from the
security-testing repository to the current (stable) repository after
being tested by the community. [2] (This QSB is being published later
than usual.) The package, which is already available to all users,
should be installed via the Qubes Update tool or its command-line
equivalents. [1]

Dom0 must be restarted afterward in order for the update to take effect.

If you use Anti Evil Maid, you will need to reseal your secret
passphrase to new PCR values, as PCR18+19 will change due to the new
microcode updates.

Credits
--------

See Intel's advisories.

References
-----------

[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html
[3] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/blob/main/releasenote.md#microcode-20260811
[4] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html
[5] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html
[6] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html
More from @qubesos
  1. Sep 19, 2026View the full list of known bugs affecting Qubes 4.3 (https://github.com/QubesOS/qubes-iss…
  2. Sep 19, 2026Qubes OS 4.3.2-rc1 is available for testing https://www.qubes-os.org/news/2026/09/18/qubes…
  3. Sep 16, 2026HEI0Vg2Gd3lAewa34zxicNsHlHh7OKsGFI027BxdIpZoEwbLzMThfA0+TH6t/JsN UEzh9lXD0cpuJIxHe0bSGrJL7…
  4. Sep 16, 2026part of the file name in most cases. And even when they do control the full path, many use…
  5. Sep 16, 2026QSB-119: Potential attacker-controlled format string in qvm-open-in-vm https://www.qubes-o…
  6. Sep 9, 2026What are some signs of an unhealthy canary? Here is a non-exhaustive list of examples: Dea…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →