Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Ubuntu Server 20.04 LTS: USN-4574-2 Critical Firmware Upgrade

red hat
Calendar Grey August 10, 2021
Dist Redhat Esm H88
A crucial patch for microcode_ctl has been issued to mitigate vulnerabilities in Red Hat Enterprise Linux. Find out more!
An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.7 Extended Update Support

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

The microcode_ctl packages provide microcode updates for Intel.
Security Fix(es):
* hw: Special Register Buffer Data Sampling (SRBDS) (CVE-2020-0543)
* hw: Vector Register Data Sampling (CVE-2020-0548)
* hw: L1D Cache Eviction Sampling (CVE-2020-0549)
* hw: vt-d related privilege escalation (CVE-2020-24489)
* hw: improper isolation of shared resources in some Intel Processors(CVE-2020-24511)
* hw: observable timing discrepancy in some Intel Processors(CVE-2020-24512)
* hw: Information disclosure issue in Intel SGX via RAPL interface (CVE-2020-8695)
* hw: Vector Register Leakage-Active (CVE-2020-8696)
* hw: Fast forward store predictor (CVE-2020-8698)

References

https://access.redhat.com/security/cve/CVE-2020-0543 https://access.redhat.com/security/cve/CVE-2020-0548 https://access.redhat.com/security/cve/CVE-2020-0549 https://access.redhat.com/security/cve/CVE-2020-8695 https://access.redhat.com/security/cve/CVE-2020-8696 https://access.redhat.com/security/cve/CVE-2020-8698 https://access.redhat.com/security/cve/CVE-2020-24489 https://access.redhat.com/security/cve/CVE-2020-24511 https://access.redhat.com/security/cve/CVE-2020-24512 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Enterprise Linux ComputeNode EUS (v. 7.7):
Source: microcode_ctl-2.1-53.18.el7_7.src.rpm
x86_64: microcode_ctl-2.1-53.18.el7_7.x86_64.rpm microcode_ctl-debuginfo-2.1-53.18.el7_7.x86_64.rpm
Red Hat Enterprise Linux Server EUS (v. 7.7):
Source: microcode_ctl-2.1-53.18.el7_7.src.rpm
x86_64: microcode_ctl-2.1-53.18.el7_7.x86_64.rpm microcode_ctl-debuginfo-2.1-53.18.el7_7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2021:3029-01
Product: Red Hat Enterprise Linux
Issue date: 2021-08-10

Topic

An update for microcode_ctl is now available for Red Hat Enterprise Linux7.7 Extended Update Support.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - x86_64

Red Hat Enterprise Linux Server EUS (v. 7.7) - x86_64

Bugs Fixed

1788786 - CVE-2020-0548 hw: Vector Register Data Sampling

1788788 - CVE-2020-0549 hw: L1D Cache Eviction Sampling

1827165 - CVE-2020-0543 hw: Special Register Buffer Data Sampling (SRBDS)

1828583 - CVE-2020-8695 hw: Information disclosure issue in Intel SGX via RAPL interface

1890355 - CVE-2020-8696 hw: Vector Register Leakage-Active

1890356 - CVE-2020-8698 hw: Fast forward store predictor

1962650 - CVE-2020-24489 hw: vt-d related privilege escalation

1962702 - CVE-2020-24511 hw: improper isolation of shared resources in some Intel Processors1962722 - CVE-2020-24512 hw: observable timing discrepancy in some Intel Processors1972332 - [rhel-7.7.z] Re-enable 06-5e-03 (SKL-H/S, CPUID 0x506e3) latest microcode updates

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here