This release mainly focuses on the detection of the new Zenbleed (CVE-2023-20593) vulnerability, among few other changes that were in line waiting for a release: * feat: detect the vulnerability and mitigation of Zenbleed (CVE-2023-20593) * feat: add the linux-firmware repository as another source for CPU microcode versions * feat: arm: add Neoverse-N2, Neoverse-V1 and. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-7228464f28 2023-08-21 00:57:49.823897 -------------------------------------------------------------------------------- Name : spectre-meltdown-checker Product : Fedora 38 Version : 0.46 Release : 1.fc38 URL : https://github.com/speed47/spectre-meltdown-checker Summary : Spectre & Meltdown vulnerability/mitigation checker for Linux Description : Spectre & Meltdown vulnerability/mitigation checker for Linux. -------------------------------------------------------------------------------- Update Information: This release mainly focuses on the detection of the new Zenbleed (CVE-2023-20593) vulnerability, among few other changes that were in line waiting for a release: * feat: detect the vulnerability and mitigation of Zenbleed (CVE-2023-20593) * feat: add the linux-firmware repository as another source for CPU microcode versions * feat: arm: add Neoverse-N2, Neoverse-V1 and Neoverse-V2 * fix: rewrite SQL to be sqlite3 > = 3.41 compatible ([#443](https://github.com/speed47/spectre-meltdown-checker/issues/443)) * fix: a /devnull file was mistakenly created on the filesystem * fix: fwdb: ignore MCEdb versions where an official Intel version exists (fixes [#430](https://github.com/speed47/spectre-meltdown-checker/issues/430)) -------------------------------------------------------------------------------- ChangeLog: * Sat Aug 12 2023 Reto Gantenbein - 0.46-1 - Update to 0.46 * Sat Jul 22 2023 Fedora Release Engineering - 0.45-4 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2232230 - 2023 ZENBLEED not covered by fedora version from april 2023 https://bugzilla.redhat.com/show_bug.cgi?id=2232230 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7228464f28' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for ucode-intel ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3271-1 Rating: moderate References: #1170446 #1173594 Cross-References: CVE-2020-8695 CVE-2020-8698 Affected Products: SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for ucode-intel fixes the following issues: - Intel CPU Microcode updated to 20201027 pre-release - CVE-2020-8695: Fixed Intel RAPL sidechannel attack (SGX) (bsc#1170446) - CVE-2020-8698: Fixed Fast Store Forward Predictor INTEL-SA-00381 (bsc#1173594) # New Platforms: | Processor | Stepping | F-M-S/PI | Old Ver | New Ver | Products |:---------------|:---------|:------------|:---------|:---------|:--------- | TGL | B1 | 06-8c-01/80 | | 00000068 | Core Gen11 Mobile | CPX-SP | A1 | 06-55-0b/bf | | 0700001e | Xeon Scalable Gen3 | CML-H | R1 | 06-a5-02/20 | | 000000e0 | Core Gen10 Mobile | CML-S62 | G1 | 06-a5-03/22 | | 000000e0 | Core Gen10 | CML-S102 | Q0 | 06-a5-05/22 | | 000000e0 | Core Gen10 | CML-U62 V2 | K0 | 06-a6-01/80 | | 000000e0 | Core Gen10 Mobile # Updated Platforms: | Processor | Stepping | F-M-S/PI | Old Ver | New Ver | Products |:---------------|:---------|:------------|:---------|:---------|:--------- | GKL-R | R0 | 06-7a-08/01 | 00000016 | 00000018 | Pentium J5040/N5030, Celeron J4125/J4025/N4020/N4120 | SKL-U/Y | D0 | 06-4e-03/c0 | 000000d6 | 000000e2 | Core Gen6 Mobile | SKL-U23e | K1 | 06-4e-03/c0 | 000000d6 | 000000e2 | Core Gen6Mobile | APL | D0 | 06-5c-09/03 | 00000038 | 00000040 | Pentium N/J4xxx, Celeron N/J3xxx, Atom x5/7-E39xx | APL | E0 | 06-5c-0a/03 | 00000016 | 0000001e | Atom x5-E39xx | SKL-H/S | R0/N0 | 06-5e-03/36 | 000000d6 | 000000e2 | Core Gen6; Xeon E3 v5 | HSX-E/EP | Cx/M1 | 06-3f-02/6f | 00000043 | 00000044 | Core Gen4 X series; Xeon E5 v3 | SKX-SP | B1 | 06-55-03/97 | 01000157 | 01000159 | Xeon Scalable | SKX-SP | H0/M0/U0 | 06-55-04/b7 | 02006906 | 02006a08 | Xeon Scalable | SKX-D | M1 | 06-55-04/b7 | 02006906 | 02006a08 | Xeon D-21xx | CLX-SP | B0 | 06-55-06/bf | 04002f01 | 04003003 | Xeon Scalable Gen2 | CLX-SP | B1 | 06-55-07/bf | 05002f01 | 05003003 | Xeon Scalable Gen2 | ICL-U/Y | D1 | 06-7e-05/80 | 00000078 | 000000a0 | Core Gen10 Mobile | AML-Y22 | H0 | 06-8e-09/10 | 000000d6 | 000000de | Core Gen8 Mobile | KBL-U/Y | H0 | 06-8e-09/c0 | 000000d6 | 000000de | Core Gen7 Mobile | CFL-U43e | D0 | 06-8e-0a/c0 | 000000d6 | 000000e0 | Core Gen8 Mobile | WHL-U | W0 | 06-8e-0b/d0 | 000000d6 | 000000de | Core Gen8 Mobile | AML-Y42 | V0 | 06-8e-0c/94 | 000000d6 | 000000de | Core Gen10 Mobile | CML-Y42 | V0 | 06-8e-0c/94 | 000000d6 | 000000de | Core Gen10 Mobile | WHL-U | V0 | 06-8e-0c/94 | 000000d6 | 000000de | Core Gen8 Mobile | KBL-G/H/S/E3 | B0 | 06-9e-09/2a | 000000d6 | 000000de | Core Gen7; Xeon E3 v6 | CFL-H/S/E3 | U0 | 06-9e-0a/22 | 000000d6 | 000000de | Core Gen8 Desktop, Mobile, Xeon E | CFL-S | B0 | 06-9e-0b/02 | 000000d6 | 000000de | Core Gen8 | CFL-H/S | P0 | 06-9e-0c/22 | 000000d6 | 000000de | Core Gen9 | CFL-H | R0 | 06-9e-0d/22 | 000000d6 | 000000de | Core Gen9 Mobile | CML-U62 | A0 | 06-a6-00/80 | 000000ca | 000000e0 | Core Gen10Mobile Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-3271=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): ucode-intel-20201027-2.7.1 References: https://www.suse.com/security/cve/CVE-2020-8695.html https://www.suse.com/security/cve/CVE-2020-8698.html https://bugzilla.suse.com/1170446 https://bugzilla.suse.com/1173594 . Canonical releases a patch for firmware-amd resolving critical vulnerabilities, enhancing overall security.. SUSE Security, Intel Microcode, System Update, Security Fixes, Ucode Intel. . LinuxSecurity.com Team
This update ships updated CPU microcode for CFL-S (Coffe Lake Desktop) models of Intel CPUs which were not yet included in the Intel microcode update released as DSA 4565-1. For details please refer to https://www.intel.com/content/dam/www/public/us/en/security-advisory/documents/IPU-2019.2-microcode-update-guidance-v1.01.pdf . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4565-2
An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2018:1737-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:1737 Issue date: 2018-05-29 CVE Names: CVE-2017-18017 CVE-2018-3639 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.3) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.3) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.3) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.3) - ppc64, ppc64le, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent memory write has occurred may see an older value and subsequently cause an updateinto the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to read privileged memory by conducting targeted cache side-channel attacks. (CVE-2018-3639) Note: This issue is present in hardware and cannot be fully fixed via software update. The updated kernel packages provide software side of the mitigation for this hardware issue. To be fully functional, up-to-date CPU microcode applied on the system might be required. Please refer to References section for further information about this issue, CPU microcode requirements and the potential performance impact. In this update, mitigation for PowerPC architecture is provided. * kernel: netfilter: use-after-free in tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c (CVE-2017-18017) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. Red Hat would like to thank Ken Johnson (Microsoft Security Response Center) and Jann Horn (Google Project Zero) for reporting CVE-2018-3639. Bug Fix(es): These updated kernel packages include also numerous bug fixes. Space precludes documenting all of these bug fixes in this advisory. See the bug fix descriptions in the related Knowledge Article: https://access.redhat.com/articles/3461451 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1531135 - CVE-2017-18017 kernel: netfilter: use-after-free in tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c 1566890 - CVE-2018-3639 hw: cpu: speculative store bypass 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v.7.3): Source: kernel-3.10.0-514.51.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-514.51.1.el7.noarch.rpm kernel-doc-3.10.0-514.51.1.el7.noarch.rpm x86_64: kernel-3.10.0-514.51.1.el7.x86_64.rpm kernel-debug-3.10.0-514.51.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.51.1.el7.x86_64.rpm kernel-devel-3.10.0-514.51.1.el7.x86_64.rpm kernel-headers-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-514.51.1.el7.x86_64.rpm perf-3.10.0-514.51.1.el7.x86_64.rpm perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm python-perf-3.10.0-514.51.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.3): x86_64: kernel-debug-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-514.51.1.el7.x86_64.rpm perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.3): Source: kernel-3.10.0-514.51.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-514.51.1.el7.noarch.rpm kernel-doc-3.10.0-514.51.1.el7.noarch.rpm ppc64: kernel-3.10.0-514.51.1.el7.ppc64.rpm kernel-bootwrapper-3.10.0-514.51.1.el7.ppc64.rpm kernel-debug-3.10.0-514.51.1.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm kernel-debug-devel-3.10.0-514.51.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-514.51.1.el7.ppc64.rpm kernel-devel-3.10.0-514.51.1.el7.ppc64.rpm kernel-headers-3.10.0-514.51.1.el7.ppc64.rpm kernel-tools-3.10.0-514.51.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm kernel-tools-libs-3.10.0-514.51.1.el7.ppc64.rpm perf-3.10.0-514.51.1.el7.ppc64.rpm perf-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm python-perf-3.10.0-514.51.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm ppc64le: kernel-3.10.0-514.51.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-514.51.1.el7.ppc64le.rpm kernel-debug-3.10.0-514.51.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-514.51.1.el7.ppc64le.rpm kernel-devel-3.10.0-514.51.1.el7.ppc64le.rpm kernel-headers-3.10.0-514.51.1.el7.ppc64le.rpm kernel-tools-3.10.0-514.51.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-514.51.1.el7.ppc64le.rpm perf-3.10.0-514.51.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm python-perf-3.10.0-514.51.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm s390x: kernel-3.10.0-514.51.1.el7.s390x.rpm kernel-debug-3.10.0-514.51.1.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-514.51.1.el7.s390x.rpm kernel-debug-devel-3.10.0-514.51.1.el7.s390x.rpm kernel-debuginfo-3.10.0-514.51.1.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-514.51.1.el7.s390x.rpm kernel-devel-3.10.0-514.51.1.el7.s390x.rpm kernel-headers-3.10.0-514.51.1.el7.s390x.rpm kernel-kdump-3.10.0-514.51.1.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-514.51.1.el7.s390x.rpm kernel-kdump-devel-3.10.0-514.51.1.el7.s390x.rpm perf-3.10.0-514.51.1.el7.s390x.rpm perf-debuginfo-3.10.0-514.51.1.el7.s390x.rpm python-perf-3.10.0-514.51.1.el7.s390x.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.s390x.rpm x86_64: kernel-3.10.0-514.51.1.el7.x86_64.rpm kernel-debug-3.10.0-514.51.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.51.1.el7.x86_64.rpm kernel-devel-3.10.0-514.51.1.el7.x86_64.rpm kernel-headers-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-514.51.1.el7.x86_64.rpm perf-3.10.0-514.51.1.el7.x86_64.rpm perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm python-perf-3.10.0-514.51.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.3): ppc64: kernel-debug-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm kernel-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-514.51.1.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-514.51.1.el7.ppc64.rpm perf-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.ppc64.rpm ppc64le: kernel-debug-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-514.51.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-514.51.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-514.51.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.ppc64le.rpm x86_64: kernel-debug-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-514.51.1.el7.x86_64.rpm perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.51.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2017-18017 https://access.redhat.com/security/cve/CVE-2018-3639 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/security/vulnerabilities/ssbd https://access.redhat.com/articles/3461451 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBWw2hHdzjgjWX9erEAQgMIg/9F2rR4PhOYLGlkZOlaWFqKijsIAEsoJfy O+oEhU3jycYwSMgckJbjHuTLhH+rLWXetWRP/BosoNPxvxiqaDRI1mVAxqZddAmp LeEHQeXnkRKHA/QjsaZiDxi83VkvdxZMcz7P8qN/gsotiFDdbu+Ku0twv+Sf3618 TyE2CJYmEv7x2h5ZLj3+PiGLtFQnSA9lvWNXId2X3lJZrDbsrrPRI1AjrCj4+XOk sLpbVLRjay5vQ9vXtKmzWtCEVXs7HWcqY+Lk4qncTgQy3I14fToqCI79nan3pdDr 1rQ0EiavFcZcJxMlQaq4L7q0U8rPRmtpqhPjhXYpQn9iK2JLsrr3S4XTESWtiFCY kN2XlNmb4AHsCxyc8DX00mBo6GTlTvmIa7/7vmI8vNg+TqUt1kJfFYXUbVW36F3o t0RySEUUJsN43bBRCEHCIjhuBUCsTSOg6sjwaGflbdDiEZbvOZg8khf70aokOmtk mIPiLoQwxzpRIIpHRwDvlepawTIHpV306K57V1itbXMA20BVZiHmrbP408RDIBsG NWh89KIFkK99lxaep4MJdknGmwylbsFBsZbuCBspRF3Iu4G4EfU9HGMROM5bRIiT moajwUeIuycqxA93edPQaz1ybjt/I1Zm5rduh6luTifF29OPux36cFi54GflwBxp kwBsFb0zdr8=1vU1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.