MGASA-2022-0065 - Updated nonfree firmware packages fix security vulnerabilities Publication date: 15 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0065.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-0066, CVE-2021-0072, CVE-2021-0076, CVE-2021-0161, CVE-2021-0164, CVE-2021-0165, CVE-2021-0166, CVE-2021-0168, CVE-2021-0170, CVE-2021-0172, CVE-2021-0173, CVE-2021-0174, CVE-2021-0175, CVE-2021-0176, CVE-2021-33139, CVE-2021-33155 This update provides new and updated nonfree firmwares and fixes atleast the following security issues: Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable escalation of privilege via local access (CVE-2021-0066 / SA-00539). Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable information disclosure via local access (CVE-2021-0072 / SA-00539). Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable denial of service via local access (CVE-2021-0076 / SA-00539). Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable escalation of privilege via local access (CVE-2021-0161, CVE-2021-0168 / SA-00539). Improper access control in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable escalation of privilege via local access (CVE-2021-0164 / SA-00539). Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0165 / SA-00539). Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable escalation of privilege via local access (CVE-2021-0166 / SA-00539). Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow an authenticated user to potentially enable information disclosure via local access (CVE-2021-0170 / SA-00539). Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0172 / SA-00539). Improper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0173 / SA-00539). Improper Use of Validation Framework in firmware for some Intel(R) PROSet/ Wireless Wi-Fi may allow a unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0174 / SA-00539). Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow an unauthenticated user to potentially enable denial of service via adjacent access (CVE-2021-0175 / SA-00539). Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged user to potentially enable denial of service via local access (CVE-2021-0176 / SA-00539). Improper conditions check in firmware for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable denial of service via adjacent access (CVE-2021-33139 / SA-00604). Improper input validation in firmware for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable denial of service via adjacent access (CVE-2021-33155 / SA-00604). Full list of firmware changes/updates: * kernel-firmware-nonfree: - cnm: add chips&media wave521c firmware - cxgb4: Update firmware to revision 1.26.6.0 - i915: Add DMC firmware v2.16 for ADL-P - marvell: add CPT firmware images - mediatek: add firmware for MT7916 - mediatek: update firmware for MT7915 - mediatek: update firmware for MT7921 bluetooth chip - mediatek: update firmware for MT7921 WiFi device - mediatek: Update MT8173 VPU firmware to v1.1.7 - Mellanox: Add new mlxsw_spectrum firmware xx.2010.1232 - QCA: Add Bluetooth nvm file for WCN685x - QCA: Update Bluetooth WCN685x 2.0 firmware to 2.0.0-00609 - QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00324 - WHENCE: add missing symlink for NanoPi R1 * iwlwifi-firmware: - add new FWs from core63-136 release - add new FWs from core66-88 release - update 9000-family firmwares to core66-88 - Update firmware file for Intel Bluetooth 9260, 9462, 9560, AX200, AX201, AX210, AX211 * radeon-firmware: - amdgpu: update yellow carp dmcub firmware * rtlwifi-firmware: - rtw88: 8822c: Update normal firmware to v9.9.11 References: - https://bugs.mageia.org/show_bug.cgi?id=30038 - https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00539.html - https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00604.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0066 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0072 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0076 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0161 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0164 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0165 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0166 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0168 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0170 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0172 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0173 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0174 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0175 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0176 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33139 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33155 SRPMS: - 8/nonfree/kernel-firmware-nonfree-20220209-1.mga8.nonfree - 8/nonfree/radeon-firmware-20220209-1.mga8.nonfree