{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/oraclelinux7els/vex/2025/cve-2025-20623-els_os-oraclelinux7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-13T02:04:52Z",
      "generator": {
        "date": "2026-06-13T02:04:52Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-20623-ELS_OS-ORACLELINUX7ELS",
      "initial_release_date": "2025-05-13T21:02:00Z",
      "revision_history": [
        {
          "date": "2025-05-13T21:02:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-13T02:04:52Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-20623"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Oracle Linux 7",
                "product": {
                  "name": "Oracle Linux 7",
                  "product_id": "Oracle-Linux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Oracle Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/microcode_ctl@2.1-73.20.0.1.el7_9?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/microcode_ctl@2.1-73.23.0.20250812.el7_9?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/microcode_ctl@2.1-73.20.0.2.el7_9?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/microcode_ctl@2.1-73.23.0.20251111.el7_9?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Oracle Corporation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@2.1-73.20.0.1.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@2.1-73.23.0.20250812.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@2.1-73.20.0.2.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@2.1-73.23.0.20251111.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-20623",
      "cwe": {
        "id": "CWE-1423",
        "name": "Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution"
      },
      "notes": [
        {
          "category": "description",
          "text": "Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Core™ processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64",
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64",
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64",
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64",
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64",
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64",
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64",
          "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-20623"
        }
      ],
      "release_date": "2025-05-13T21:02:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-06-12T13:03:59.134949Z",
          "details": "This is a local-only, high-complexity speculative side‑channel that requires an authenticated attacker to run code and precisely manipulate shared branch‑predictor state (often requiring co-residency on the same physical core), which materially limits practical exploitability in VM/server workloads. The impact is confined to confidentiality (no integrity or availability effect), and the affected hardware scope is limited to certain 10th‑generation Intel Core mobile processors rather than common server‑class CPUs. Given these constraints, it is reasonable to treat CVE‑2025‑20623 as low priority in centrally managed enterprise environments.",
          "product_ids": [
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.1.el7_9.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.20.0.2.el7_9.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20250812.el7_9.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.tuxcare.els1.x86_64",
            "Oracle-Linux-7:microcode_ctl-2:2.1-73.23.0.20251111.el7_9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}