{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2023/cve-2023-22655-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T15:54:08Z",
      "generator": {
        "date": "2026-07-28T15:54:08Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2023-22655-ELS_OS-RHEL7ELS",
      "initial_release_date": "2023-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2023-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T15:54:08Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2023-22655"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/microcode_ctl@2.1-73.25.el7_9?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/microcode_ctl@2.1-73.26.el7_9?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@2.1-73.25.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
                "product": {
                  "name": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
                  "product_id": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/microcode_ctl@2.1-73.26.el7_9.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.25.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.25.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "microcode_ctl-2:2.1-73.26.el7_9.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
        },
        "product_reference": "microcode_ctl-2:2.1-73.26.el7_9.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-22655",
      "cwe": {
        "id": "CWE-693",
        "name": "Protection Mechanism Failure"
      },
      "notes": [
        {
          "category": "description",
          "text": "Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
          "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64",
          "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
          "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-22655"
        }
      ],
      "release_date": "2024-03-12T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T11:56:50.300915Z",
          "details": "This vulnerability is local-only, requires a highly privileged attacker, and is reachable only when Intel SGX or TDX is explicitly enabled and in active use—systems not using these features are outside the vulnerable path. In virtualized enterprise deployments, guest VMs generally lack access to the trusted-execution configuration registers involved, making practical exploitation by a tenant implausible. With no availability impact and only low confidentiality impact per the CVSS metrics, the likely blast radius is limited, so this can be safely deprioritized.",
          "product_ids": [
            "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
            "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64",
            "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
            "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.tuxcare.els1.x86_64",
            "Red-Hat-7:microcode_ctl-2:2.1-73.25.el7_9.x86_64",
            "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.tuxcare.els1.x86_64",
            "Red-Hat-7:microcode_ctl-2:2.1-73.26.el7_9.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}