MGASA-2020-0298 - Updated microcode packages fix security vulnerability

Publication date: 31 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0298.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-0543,
     CVE-2020-0548,
     CVE-2020-0549

Incomplete cleanup from specific special register read operations in some
Intel(R) Processors may allow an authenticated user to potentially enable
information disclosure via local access. (CVE-2020-0543)

Cleanup errors in some Intel(R) Processors may allow an authenticated user
to potentially enable information disclosure via local access.
(CVE-2020-0548)

Cleanup errors in some data cache evictions for some Intel(R) Processors
may allow an authenticated user to potentially enable information
disclosure via local access. (CVE-2020-0549)

References:
- https://bugs.mageia.org/show_bug.cgi?id=26783
- https://www.debian.org/security/2020/dsa-4701
- https://access.redhat.com/errata/RHSA-2020:2431
- https://usn.ubuntu.com/4385-1/
- https://usn.ubuntu.com/4385-2/
- https://lists.fedoraproject.org/archives/list/[email protected]/thread/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0543
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0548
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0549

SRPMS:
- 7/nonfree/microcode-0.20200616-1.mga7.nonfree