Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.2: 2020:1923-1 Moderate: Ucode-Intel Sidechannel Fix

opensuse
Calendar Grey November 14, 2020
Dist Opensuse Esm H88
The update for ucode-intel addresses critical Intel processor microcode vulnerabilities on openSUSE Leap 15.2 categorized as high severity.
An update that fixes two vulnerabilities is now available.

Description

This update for ucode-intel fixes the following issues:

- Intel CPU Microcode updated to 20201027 prerelease

- CVE-2020-8695: Fixed Intel RAPL sidechannel attack (SGX) (bsc#1170446)

- CVE-2020-8698: Fixed Fast Store Forward Predictor INTEL-SA-00381

(bsc#1173594)

# New Platforms: | Processor | Stepping | F-M-S/PI | Old Ver |

New Ver | Products

|:---------------|:---------|:------------|:---------|:---------|:--------- | TGL | B1 | 06-8c-01/80 | | 00000068 | Core

Gen11 Mobile | CPX-SP | A1 | 06-55-0b/bf | |

0700001e | Xeon Scalable Gen3 | CML-H | R1 | 06-a5-02/20

| | 000000e0 | Core Gen10 Mobile | CML-S62 | G1 |

06-a5-03/22 | | 000000e0 | Core Gen10 | CML-S102 | Q0

| 06-a5-05/22 | | 000000e0 | Core Gen10 | CML-U62 V2 |

K0 | 06-a6-01/80 | | 000000e0 | Core Gen10 Mobile # Updated

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1923=1

Package List

- openSUSE Leap 15.2 (x86_64):

ucode-intel-20201027-lp152.2.4.1

References

https://www.suse.com/security/cve/CVE-2020-8695.html

https://www.suse.com/security/cve/CVE-2020-8698.html

https://bugzilla.suse.com/1170446

https://bugzilla.suse.com/1173594

openSUSE Security Announce mailing list -- security-announce@lists.opensuse.org

To unsubscribe, email security-announce-leave@lists.opensuse.org

List Netiquette: https://en.opensuse.org/openSUSE:Mailing_list_netiquette

List Archives:

Announcement ID: openSUSE-SU-2020:1923-1
Rating: moderate
Affected Products: openSUSE Leap 15.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here