Ubuntu Security Notices USN-8068-1 USN-8068-1: Intel Microcode vulnerability Publication date 3 March 2026 Overview The system could be made to run programs as an administrator. Releases 25.10 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages intel-microcode - Processor microcode for Intel CPUs Details Sergiu Ghetie discovered that some Intel® processors did not properly handle values in the microcode flow. A local authenticated user could potentially use this issue to escalate their privileges. Sergiu Ghetie discovered that some Intel® processors did not properly handle values in the microcode flow. A local authenticated user could potentially use this issue to escalate their privileges. Update instructions After a standard system update you need to reboot your computer to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 25.10 questing intel-microcode – 3.20260210.0ubuntu0.25.10.1 24.04 LTS noble intel-microcode – 3.20260210.0ubuntu0.24.04.1 22.04 LTS jammy intel-microcode – 3.20260210.0ubuntu0.22.04.1 20.04 LTS focal intel-microcode – 3.20260210.0ubuntu0.20.04.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic intel-microcode – 3.20260210.0ubuntu0.18.04.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial intel-microcode – 3.20260210.0ubuntu0.16.04.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2025-31648 CVE-2025-31648
A vulnerability in Intel processor microcode (CVE-2025-31648, CVSS 3.9 LOW) allows a local authenticated attacker to potentially escalate privileges by exploiting improper handling of values in the microcode flow. The flaw affects multiple Ubuntu LTS releases, and the fix requires updating the `intel-microcode` package to version `3.20260210.0ubuntu0.*` specific to each release, followed by a system reboot.