Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Warning: Undefined variable $read_more_description in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 1551

SUSE: 2019:1235-1 Important: ucode-intel Data Leak Threats

suse
Calendar Grey May 14, 2019
Dist Suse Esm H88
An important update from SUSE for ucode-intel mitigates potential data exposure vulnerabilities in Intel processors. Ensure your system's safety by applying the newest fixes.
An update that fixes four vulnerabilities is now available

Summary

This update for ucode-intel fixes the following issues: This update contains the Intel QSR 2019.1 Microcode release (bsc#1111331) Four new speculative execution information leak issues have been identified in Intel CPUs. (bsc#1111331) - CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS) - CVE-2018-12127: Microarchitectural Fill Buffer Data Sampling (MFBDS) - CVE-2018-12130: Microarchitectural Load Port Data Samling (MLPDS) - CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory (MDSUM) These updates contain the CPU Microcode adjustments for the software mitigations. For more information on this set of vulnerabilities, check out https://support.scc.suse.com/s/kb?language=en_US Release notes: - Processor Identifier Version Products

References

#1111331

Cross- CVE-2018-12126 CVE-2018-12127 CVE-2018-12130

CVE-2019-11091

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP4

SUSE Linux Enterprise Desktop 12-SP3

SUSE Enterprise Storage 4

SUSE CaaS Platform 3.0

https://www.suse.com/security/cve/CVE-2018-12126.html

https://www.suse.com/security/cve/CVE-2018-12127.html

https://www.suse.com/security/cve/CVE-2018-1213...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1235-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here