Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 2019-0174: Kernel Update for Microarchitectural Data Sampling Issues

mageia
Calendar Grey May 16, 2019
Dist Mageia Esm H88
Ubuntu 2020-0298 enhances protections against Spectre flaws in AMD processors, bolstering safety for clients.
This kernel update provides the upstream 4.14.119 that adds the kernel side mitigations for the Microarchitectural Data Sampling (MDS, also called ZombieLoad attack) vulnerabilitie...

Summary

This kernel update provides the upstream 4.14.119 that adds the kernel side mitigations for the Microarchitectural Data Sampling (MDS, also called ZombieLoad attack) vulnerabilities in Intel processors that can allow attackers to retrieve data being processed inside a CPU. To complete the mitigations new microcode is also needed, either by installing the microcode-0.20190514-1.mga6 package, or get an updated bios / uefi firmware from the motherboard vendor.
The fixed / mitigated issues are:
Modern Intel microprocessors implement hardware-level micro-optimizations to improve the performance of writing data back to CPU caches. The write operation is split into STA (STore Address) and STD (STore Data) sub-operations. These sub-operations allow the processor to hand-off address generation logic into these sub-operations for optimized writes. Both of these sub-operations write to a shared distributed processor structure called the 'processor store buffer'. As a result, an unprivileged at...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=24820

- https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html

- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.117

- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.118

- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.119

- https://www.cve.org/CVERecord?id=CVE-2018-12126

- https://www.cve.org/CVERecord?id=CVE-2018-12127

- https://www.cve.org/CVERecord?id=CVE-2018-12130

- https://www.cve.org/CVERecord?id=CVE-2019-11091

Resolution

SRPMS

- 6/core/kernel-4.14.119-1.mga6

- 6/core/kernel-userspace-headers-4.14.119-1.mga6

- 6/core/kmod-vboxadditions-6.0.6-3.mga6

- 6/core/kmod-virtualbox-6.0.6-3.mga6

- 6/core/kmod-xtables-addons-2.13-85.mga6

Severity
medium
Lowest
Low
Medium
High
Critical

Publication date: 16 May 2019
URL: https://advisories.mageia.org/MGASA-2019-0174.html
Type: security
CVE: CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here