Mageia 2022-0304: microcode security update | LinuxSecurity.com
MGASA-2022-0304 - Updated microcode packages fix security vulnerability

Publication date: 25 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0304.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-21233

Updated microcode packages fix security vulnerability:

Improper isolation of shared resources in some Intel(R) Processors
may allow a privileged user to potentially enable information
disclosure via local access (CVE-2022-21233, intel-sa-00657).

For more info, see the refenced advisory and release notes.

References:
- https://bugs.mageia.org/show_bug.cgi?id=30748
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00657.html
- https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220809
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21233

SRPMS:
- 8/nonfree/microcode-0.20220809-1.mga8.nonfree

Mageia 2022-0304: microcode security update

Updated microcode packages fix security vulnerability: Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable informa...

Summary

Updated microcode packages fix security vulnerability:
Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access (CVE-2022-21233, intel-sa-00657).
For more info, see the refenced advisory and release notes.

References

- https://bugs.mageia.org/show_bug.cgi?id=30748

- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00657.html

- https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220809

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21233

Resolution

MGASA-2022-0304 - Updated microcode packages fix security vulnerability

SRPMS

- 8/nonfree/microcode-0.20220809-1.mga8.nonfree

Severity
Publication date: 25 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0304.html
Type: security
CVE: CVE-2022-21233

We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.