MGASA-2020-0298 - Updated microcode packages fix security vulnerability

Publication date: 31 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0298.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-0543,
     CVE-2020-0548,
     CVE-2020-0549

Incomplete cleanup from specific special register read operations in some
Intel(R) Processors may allow an authenticated user to potentially enable
information disclosure via local access. (CVE-2020-0543)

Cleanup errors in some Intel(R) Processors may allow an authenticated user
to potentially enable information disclosure via local access.
(CVE-2020-0548)

Cleanup errors in some data cache evictions for some Intel(R) Processorsmay allow an authenticated user to potentially enable information
disclosure via local access. (CVE-2020-0549)

References:
- https://bugs.mageia.org/show_bug.cgi?id=26783
- https://www.debian.org/security/2020/dsa-4701
- https://access.redhat.com/errata/RHSA-2020:2431
- https://ubuntu.com/security/notices/USN-4385-1
- https://ubuntu.com/security/notices/USN-4385-2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0543
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0548
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0549

SRPMS:
- 7/nonfree/microcode-0.20200616-1.mga7.nonfree

Mageia 2020-0298: microcode security update

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local...

Summary

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0543)
Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0548)
Cleanup errors in some data cache evictions for some Intel(R) Processorsmay allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0549)

References

- https://bugs.mageia.org/show_bug.cgi?id=26783

- https://www.debian.org/security/2020/dsa-4701

- https://access.redhat.com/errata/RHSA-2020:2431

- https://ubuntu.com/security/notices/USN-4385-1

- https://ubuntu.com/security/notices/USN-4385-2

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0543

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0548

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0549

Resolution

MGASA-2020-0298 - Updated microcode packages fix security vulnerability

SRPMS

- 7/nonfree/microcode-0.20200616-1.mga7.nonfree

Severity
Publication date: 31 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0298.html
Type: security
CVE: CVE-2020-0543, CVE-2020-0548, CVE-2020-0549

Related News