QSB-117: Intel CPU firmware vulnerabilities
https://www.qubes-os.org/news/2026/08/28/qsb-117/
We have published Qubes Security Bulletin (QSB) 117: Intel CPU firmware vulnerabilities (https://github.com/QubesOS/qubes-secpack/blob/2fae4b5eb43fae0b3bd58cc50444aac283d702fb/QSBs/qsb-117-2026.txt). The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
Qubes Security Bulletin 117
---===[ Qubes Security Bulletin 117 ]===---
2026-08-28
Intel CPU firmware vulnerabilities
User action
------------
Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.
Summary
--------
On 2026-08-11, Intel published "microcode-20260811 Release," [3] which
is associated with several Intel security advisories. Among these
security advisories, we suspect the following may apply to Qubes OS:
- "2026.3 IPU, Intel Processor Load Value Injection Zero Data Advisory"
(INTEL-SA-01423) [4]
- "Intel Processor Firmware Advisory - 01428" (INTEL-SA-01428) [5]
- "Intel Processor Firmware Advisory - 01435" (INTEL-SA-01435) [6]
- "2026.3 IPU, Intel Processor Firmware Advisory" (INTEL-SA-01441) [7]
- "2026.3 IPU, Intel Xeon Processor Firmware Advisory"
(INTEL-SA-01442) [8]
Unfortunately, these advisories do not provide sufficient information
for us to make a definitive assessment about the extent to which these
vulnerabilities affect the security of Qubes OS. Based on the limited
information available, we cannot exclude possibility of a cross-qube
attack.
Impact
-------
On affected systems, an attacker who has managed to compromise one qube
can attempt to exploit these vulnerabilities in order to infer data
belonging to other qubes or escalate their privileges.
Affected systems
-----------------
Only systems with one of the following Intel CPUs are affected by at
least some of the advisories:
- 10th Generation Intel Core
- 11th Generation Intel Core
- Intel Core Ultra, Series 1 to 3
- various Xeon variants
For a more detailed list of affected products see Intel's advisories.
Note: As of this writing, Intel has withdrawn the relevant update for
Meteor Lake (Intel Core Ultra Series 2) CPUs "due to functional issues"
[9]. Due to limited information, the impact of the vulnerabilities
discussed in this bulletin on systems without the relevant update is
unclear.
Patching
---------
The following package contains the security update that addresses the
vulnerability described in this bulletin:
For Qubes 4.3, in dom0:
- microcode_ctl version 2.1.20260812
Note: This package has already finished migrating from the
security-testing repository to the current (stable) repository after
being tested by the community. [2] (This QSB is being published later
than usual.) The package, which is already available to all users,
should be installed via the Qubes Update tool or its command-line
equivalents. [1]
Dom0 must be restarted afterward in order for the update to take effect.
If you use Anti Evil Maid, you will need to reseal your secret
passphrase to new PCR values, as PCR18+19 will change due to the new
microcode updates.
Credits
--------
See Intel's advisories.
References
-----------
[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html
[3] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/blob/main/releasenote.md#microcode-20260811
[4] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html
[5] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html
[6] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html
Post #1203
122