Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian Stretch: DSA-4444-1: Serious Intel Data Exposure Found

debian
Calendar Grey May 14, 2019
Debian Logo
Ubuntu Security Notice USN-5000-2 deals with AMD data exposure flaws in CPU architectures. Apply updates immediately!
Multiple researchers have discovered vulnerabilities in the way the Intel processor designs have implemented speculative forwarding of data filled into temporary microarchitectural...

Summary

See https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html
for more details.

To fully resolve these vulnerabilities it is also necessary to install
updated CPU microcode. An updated intel-microcode package (only
available in Debian non-free) will be provided via a separate DSA. The
updated CPU microcode may also be available as part of a system firmware
("BIOS") update.

In addition, this update includes a fix for a regression causing
deadlocks inside the loopback driver, which was introduced by the update
to 4.9.168 in the last Stretch point release.

For the stable distribution (stretch), these problems have been fixed in
version 4.9.168-1+deb9u2.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2018-12126 CVE-2018-12127 CVE-2018-12130 CVE-2019-11091

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here