Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Critical AMD Microcode Patch for Fedora 27 Released on 2018:0815-1

opensuse
Calendar Grey March 16, 2018
Dist Opensuse Esm H88
Important openSUSE patch addresses Intel microcode security weakness, introducing enhanced defenses against Spectre vulnerabilities.
An update that fixes one vulnerability is now available.

Description

This update for ucode-intel fixes the following issues:

The Intel CPU microcode version was updated to version 20180312.

This update enables the IBPB+IBRS based mitigations of the Spectre v2

flaws (boo#1085207 CVE-2017-5715)

- New Platforms

- BDX-DE EGW A0 6-56-5:10 e000009

- SKX B1 6-55-3:97 1000140

- Updates

- SNB D2 6-2a-7:12 29->2d

- JKT C1 6-2d-6:6d 619->61c

- JKT C2 6-2d-7:6d 710->713

- IVB E2 6-3a-9:12 1c->1f

- IVT C0 6-3e-4:ed 428->42c

- IVT D1 6-3e-7:ed 70d->713

- HSW Cx/Dx 6-3c-3:32 22->24

- HSW-ULT Cx/Dx 6-45-1:72 20->23

- CRW Cx 6-46-1:32 17->19

- HSX C0 6-3f-2:6f 3a->3c

- HSX-EX E0 6-3f-4:80 0f->11

- BDW-U/Y E/F 6-3d-4:c0 25->2a

- BDW-H E/G 6-47-1:22 17->1d

- BDX-DE V0/V1 6-56-2:10 0f->15

- BDW-DE V2 6-56-3:10 700000d->7000012

- BDW-DE Y0 6-56-4:10 f00000a->f000011

- SKL-U/Y D0 6-4e-3:c0 ba->c2

- SKL R0 6-5e-3:36 ba->c2

- KBL-U/Y H0 6-8e-9:c0...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-266=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (i586 x86_64):

ucode-intel-20180312-22.1

ucode-intel-blob-20180312-22.1

ucode-intel-debuginfo-20180312-22.1

ucode-intel-debugsource-20180312-22.1

References

https://www.suse.com/security/cve/CVE-2017-5715.html

https://bugzilla.suse.com/1085207

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0710-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here