This update for ucode-intel fixes the following issues:
Updated to Intel CPU Microcode 20210608 release.
- CVE-2020-24513: A domain bypass transient execution vulnerability was
discovered on some Intel Atom processors that use a
micro-architectural incident channel. (INTEL-SA-00465 bsc#1179833)
See also:
https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=https://www.intel.com/content/www/us/en/404.html?ref=https://https://www.intel.com/content/www/us/en/404.html?ref=
0465.html
- CVE-2020-24511: The IBRS feature to mitigate Spectre variant 2
transient execution side channel vulnerabilities may...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-876=1
- openSUSE Leap 15.2 (x86_64):
ucode-intel-20210525-lp152.2.17.1
https://www.suse.com/security/cve/CVE-2020-24489.html
https://www.suse.com/security/cve/CVE-2020-24511.html
https://www.suse.com/security/cve/CVE-2020-24512.html
https://www.suse.com/security/cve/CVE-2020-24513.html
https://bugzilla.suse.com/1179833
https://bugzilla.suse.com/1179836
https://bugzilla.suse.com/1179837
https://bugzilla.suse.com/1179839
Get the latest Linux and open source security news straight to your inbox.