The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12580 http://linux.oracle.com/errata/ELSA-2024-12580.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: iwlax2xx-firmware-20240715-999.34.el8.noarch.rpm iwl1000-firmware-39.31.5.1-999.34.el8.noarch.rpm iwl100-firmware-39.31.5.1-999.34.el8.noarch.rpm iwl105-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl135-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl2000-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl2030-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl3160-firmware-25.30.13.0-999.34.el8.noarch.rpm iwl3945-firmware-15.32.2.9-999.34.el8.noarch.rpm iwl4965-firmware-228.61.2.24-999.34.el8.noarch.rpm iwl5000-firmware-8.83.5.1_1-999.34.el8.noarch.rpm iwl5150-firmware-8.24.2.2-999.34.el8.noarch.rpm iwl6000-firmware-9.221.4.1-999.34.el8.noarch.rpm iwl6000g2a-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl6000g2b-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl6050-firmware-41.28.5.1-999.34.el8.noarch.rpm iwl7260-firmware-25.30.13.0-999.34.el8.noarch.rpm libertas-sd8686-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm libertas-sd8787-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm libertas-usb8388-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm libertas-usb8388-olpc-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm linux-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm linux-firmware-core-20240715-999.34.git4c8fb21e.el8.noarch.rpm aarch64: iwlax2xx-firmware-20240715-999.34.el8.noarch.rpm iwl1000-firmware-39.31.5.1-999.34.el8.noarch.rpm iwl100-firmware-39.31.5.1-999.34.el8.noarch.rpm iwl105-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl135-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl2000-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl2030-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl3160-firmware-25.30.13.0-999.34.el8.noarch.rpm iwl3945-firmware-15.32.2.9-999.34.el8.noarch.rpm iwl4965-firmware-228.61.2.24-999.34.el8.noarch.rpm iwl5000-firmware-8.83.5.1_1-999.34.el8.noarch.rpm iwl5150-firmware-8.24.2.2-999.34.el8.noarch.rpm iwl6000-firmware-9.221.4.1-999.34.el8.noarch.rpm iwl6000g2a-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl6000g2b-firmware-18.168.6.1-999.34.el8.noarch.rpm iwl6050-firmware-41.28.5.1-999.34.el8.noarch.rpm iwl7260-firmware-25.30.13.0-999.34.el8.noarch.rpm libertas-sd8686-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm libertas-sd8787-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm libertas-usb8388-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm libertas-usb8388-olpc-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm linux-firmware-20240715-999.34.git4c8fb21e.el8.noarch.rpm linux-firmware-core-20240715-999.34.git4c8fb21e.el8.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//linux-firmware-20240715-999.34.git4c8fb21e.el8.src.rpm Related CVEs: CVE-2023-31315 Description of changes: [20240715-999.34.git4c8fb21e.el8] - Rebase to latest upstream [Orabug: 36826157] _______________________________________________ El-errata mailing list
* bsc#1215823 * bsc#1215831 Cross-References: * CVE-2021-26345 . # Security update for kernel-firmware Announcement ID: SUSE-SU-2023:4664-1 Rating: important References: * bsc#1215823 * bsc#1215831 Cross-References: * CVE-2021-26345 * CVE-2021-46766 * CVE-2021-46774 * CVE-2022-23820 * CVE-2022-23830 * CVE-2023-20519 * CVE-2023-20521 * CVE-2023-20526 * CVE-2023-20533 * CVE-2023-20566 * CVE-2023-20592 CVSS scores: * CVE-2021-26345 ( SUSE ): 1.6 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2021-26345 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2021-46766 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N * CVE-2021-46766 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2021-46774 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L * CVE-2021-46774 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-23820 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2022-23820 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-23830 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2022-23830 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-20519 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-20519 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2023-20521 ( SUSE ): 3.3 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L * CVE-2023-20521 ( NVD ): 5.7 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2023-20526 ( SUSE ): 1.9 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N * CVE-2023-20526 ( NVD ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-20533 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:H * CVE-2023-20533 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-20566 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2023-20566 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N *CVE-2023-20592 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2023-20592 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP4 * openSUSE Leap 15.4 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for kernel-firmware fixes the following issues: Update AMD ucode to 20231030 (bsc#1215831): * CVE-2022-23820: Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution. * CVE-2021-46774: Insufficient input validation in ABL may enable a privileged attacker to perform arbitrary DRAM writes, potentially resulting in code execution and privilege escalation. * CVE-2023-20533: Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker using DMA to read/write from/to invalid DRAM address potentially resulting in denial-of-service. 0 CVE-2023-20519: A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity. * CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity. * CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. * CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality. * CVE-2022-23830: SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity. * CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality. * CVE-2021-26345: Failure to validate the value in APCB may allow an attacker with physical access to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service. * CVE-2023-20592: Issue with INVD instruction aka CacheWarpAttack (bsc#1215823). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-4664=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4664=1 SUSE-2023-4664=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4664=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4664=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4664=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4664=1 * Basesystem Module 15-SP4 zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP4-2023-4664=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-4664=1 ## Package List: * openSUSE Leap Micro 5.4 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 * kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 * kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 * kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 * kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 * kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 * kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 * kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 * openSUSE Leap 15.4 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 *kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 * kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 * kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 * kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 * kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 * kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 * kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 * kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 *kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 * kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 * kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 * kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 * kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 * kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 * kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 * kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 *kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 * kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 * kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 * kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 * kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 * kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 * kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 * kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 *kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 * kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 * kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 * kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 * kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 * kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 * kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 * kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 *kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 * kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 * kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 * Basesystem Module 15-SP4 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 * kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 * kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 * kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 * kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 * kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 *kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 * kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 * openSUSE Leap Micro 5.3 (noarch) * kernel-firmware-amdgpu-20220509-150400.4.25.1 * kernel-firmware-realtek-20220509-150400.4.25.1 * kernel-firmware-usb-network-20220509-150400.4.25.1 * kernel-firmware-media-20220509-150400.4.25.1 * kernel-firmware-mediatek-20220509-150400.4.25.1 * kernel-firmware-i915-20220509-150400.4.25.1 * kernel-firmware-atheros-20220509-150400.4.25.1 * kernel-firmware-dpaa2-20220509-150400.4.25.1 * kernel-firmware-serial-20220509-150400.4.25.1 * kernel-firmware-marvell-20220509-150400.4.25.1 * kernel-firmware-intel-20220509-150400.4.25.1 * kernel-firmware-liquidio-20220509-150400.4.25.1 * kernel-firmware-prestera-20220509-150400.4.25.1 * kernel-firmware-mwifiex-20220509-150400.4.25.1 * kernel-firmware-ath11k-20220509-150400.4.25.1 * kernel-firmware-ath10k-20220509-150400.4.25.1 * kernel-firmware-all-20220509-150400.4.25.1 * kernel-firmware-nvidia-20220509-150400.4.25.1 * kernel-firmware-nfp-20220509-150400.4.25.1 * kernel-firmware-brcm-20220509-150400.4.25.1 * kernel-firmware-ueagle-20220509-150400.4.25.1 * kernel-firmware-ti-20220509-150400.4.25.1 * kernel-firmware-platform-20220509-150400.4.25.1 * kernel-firmware-iwlwifi-20220509-150400.4.25.1 * ucode-amd-20220509-150400.4.25.1 * kernel-firmware-qlogic-20220509-150400.4.25.1 *kernel-firmware-network-20220509-150400.4.25.1 * kernel-firmware-radeon-20220509-150400.4.25.1 * kernel-firmware-qcom-20220509-150400.4.25.1 * kernel-firmware-bnx2-20220509-150400.4.25.1 * kernel-firmware-chelsio-20220509-150400.4.25.1 * kernel-firmware-sound-20220509-150400.4.25.1 * kernel-firmware-mellanox-20220509-150400.4.25.1 * kernel-firmware-bluetooth-20220509-150400.4.25.1 ## References: * https://www.suse.com/security/cve/CVE-2021-26345.html * https://www.suse.com/security/cve/CVE-2021-46766.html * https://www.suse.com/security/cve/CVE-2021-46774.html * https://www.suse.com/security/cve/CVE-2022-23820.html * https://www.suse.com/security/cve/CVE-2022-23830.html * https://www.suse.com/security/cve/CVE-2023-20519.html * https://www.suse.com/security/cve/CVE-2023-20521.html * https://www.suse.com/security/cve/CVE-2023-20526.html * https://www.suse.com/security/cve/CVE-2023-20533.html * https://www.suse.com/security/cve/CVE-2023-20566.html * https://www.suse.com/security/cve/CVE-2023-20592.html * https://bugzilla.suse.com/show_bug.cgi?id=1215823 * https://bugzilla.suse.com/show_bug.cgi?id=1215831 . Canonical disclosed a significant security patch for its Ubuntu kernel, tackling weaknesses to improve overall system resilience.. SUSE Linux, Firmware Update, Patch Management, System Security, Kernel Fixes. . Severity: Important. LinuxSecurity.com Team
An update for linux-firmware is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: linux-firmware security and bug fix update Advisory ID: RHSA-2020:5416-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:5416 Issue date: 2020-12-15 CVE Names: CVE-2020-12321 ==================================================================== 1. Summary: An update for linux-firmware is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS EUS (v. 8.2) - noarch 3. Description: The linux-firmware packages contain all of the firmware files that are required by various devices to operate. Security Fix(es): * hardware: buffer overflow in bluetooth firmware (CVE-2020-12321) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Remove buggy ucode patch from microcode_amd_fam17h.bin (BZ#1872773) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1893914 - CVE-2020-12321 hardware: buffer overflow in bluetooth firmware 6. PackageList: Red Hat Enterprise Linux BaseOS EUS (v. 8.2): Source: linux-firmware-20191202-99.gite8a0f4c9.el8_2.src.rpm noarch: iwl100-firmware-39.31.5.1-99.el8_2.1.noarch.rpm iwl1000-firmware-39.31.5.1-99.el8_2.1.noarch.rpm iwl105-firmware-18.168.6.1-99.el8_2.1.noarch.rpm iwl135-firmware-18.168.6.1-99.el8_2.1.noarch.rpm iwl2000-firmware-18.168.6.1-99.el8_2.1.noarch.rpm iwl2030-firmware-18.168.6.1-99.el8_2.1.noarch.rpm iwl3160-firmware-25.30.13.0-99.el8_2.1.noarch.rpm iwl3945-firmware-15.32.2.9-99.el8_2.1.noarch.rpm iwl4965-firmware-228.61.2.24-99.el8_2.1.noarch.rpm iwl5000-firmware-8.83.5.1_1-99.el8_2.1.noarch.rpm iwl5150-firmware-8.24.2.2-99.el8_2.1.noarch.rpm iwl6000-firmware-9.221.4.1-99.el8_2.1.noarch.rpm iwl6000g2a-firmware-18.168.6.1-99.el8_2.1.noarch.rpm iwl6000g2b-firmware-18.168.6.1-99.el8_2.1.noarch.rpm iwl6050-firmware-41.28.5.1-99.el8_2.1.noarch.rpm iwl7260-firmware-25.30.13.0-99.el8_2.1.noarch.rpm libertas-sd8686-firmware-20191202-99.gite8a0f4c9.el8_2.noarch.rpm libertas-sd8787-firmware-20191202-99.gite8a0f4c9.el8_2.noarch.rpm libertas-usb8388-firmware-20191202-99.gite8a0f4c9.el8_2.noarch.rpm libertas-usb8388-olpc-firmware-20191202-99.gite8a0f4c9.el8_2.noarch.rpm linux-firmware-20191202-99.gite8a0f4c9.el8_2.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12321 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX9h7VNzjgjWX9erEAQjn7Q/6A07Jb17C8mj0gFmwZRr4xT+uT9DlpTKp xJsmyac9aUPrgknP1TYyzVJDzdbswkOteZXoAtLFq7W9sxGiXhQWhnbHGEPvojMB h28SsqObz3+Mnet8F30Q8hihfLG7V3hztc/7SKoXLgrib+gwQSgP8i/v/eomMfj3 LKc4szOCPqixsfNNHY9pJuKRu5Jmq5TvuwpWHlfr2BD4m0I35DK3z3RvCXZrxtok bKr5v/e2a7Ovg8U3HnN/hlBwOLCTe+MxhxhUa9zOk0I5+T0eq31EUFQv47rmnWDV RFqlXeArvYzY1bWtGBtOv7LuXGfScYfHPFP5/PkUUvP1cz5fokzF/CEd/gyDdO2q hxh8fW1f3UdddIqw6yry9QbJQkgL3FrZc1K7ctPPjgOXnU7uHSCzOf1uNgdfUGAq PFt1GHrS75WI7TjD9iVWrm9ruizWY9k5HrSp2o2D+ujw6LJyKEknu1R8pMNuQ/Rf oV7Hv4yWDum56QZTWDqq2jui+c2WIQgEBLULG6E6Fj/h4Dk7bip7tDBI8aUqvkbj Drucl7V4VWIynUwbB/gnAfXo7Y+IYaDz9Eo9oV0+Uf4S0p51+qx9dhLIvZIBUuj0 jugFHe3VdOvVnon5Q3TuNFcfN/d17fatOIytFLpEUm93zCs6kfQukOLlqiRQ0o1U IaO4BidcNpI=eDEq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
This update is based on upstream 5.4.6 and fixes various potential security issues related to buffer overflows, double frees, NUll pointer dereferences, improper / missing input validations and so on. It also adds other bugfixes all over the kernel. . MGASA-2019-0414 - Updated kernel packages fix security vulnerabilities Publication date: 25 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0414.html Type: security Affected Mageia releases: 7 This update is based on upstream 5.4.6 and fixes various potential security issues related to buffer overflows, double frees, NUll pointer dereferences, improper / missing input validations and so on. It also adds other bugfixes all over the kernel. Other fixes added in this update: - x86/MCE/AMD: Do not use rdmsr_safe_on_cpu() in smca_configure(), fixing an deadlock issue. - x86/mm: Split vmalloc_sync_all(), fixing up big performance regressions in some x86_64 workloads (example: reaim.jobs_per_min -79.7% regression) - The Intel cpu/gpu specific security fixes in upstream 5.3.11 broke RC6 and that prevents CPUs from entering C-states, causing higher power consumption. This update adds upstream fixes to restore RC6 to a working state (fdo#112315) - radeon changes in upstream 5.4 to remove the 'need_dma32 flag' has been reverted as it caused radeon to malfunction on 32bit kernels - iwlwifi fixes for firmware crashes (mga#25926), failures on warm reboot, and performance fixes WireGuard has been updated to 0.0.20191219. For other fixes in this update, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=25897 - https://bugs.mageia.org/show_bug.cgi?id=25926 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.3 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.4 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.5 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.6 SRPMS: - 7/core/kernel-5.4.6-2.mga7 - 7/core/kmod-virtualbox-6.0.14-16.mga7 -7/core/kmod-xtables-addons-3.7-6.mga7 - 7/core/wireguard-tools-0.0.20191219-1.mga7 . Critical vulnerabilities in the Mageia kernel have been patched in a security update, resolving significant buffer overflow risks and enhancing overall performance stability.. Mageia Kernel Update, Security Fix, Buffer Overflow, Input Validation Issues. . LinuxSecurity.com Team
An update that solves one vulnerability and has two fixes is now available. . SUSE Security Update: Security update for kernel-firmware ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1803-1 Rating: moderate References: #1136334 #1136498 #1139383 Cross-References: CVE-2019-9836 Affected Products: SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for kernel-firmware fixes the following issues: kernel-firmware was updated to version 20190618: * cavium: Add firmware for CNN55XX crypto driver. * linux-firmware: Update firmware file for Intel Bluetooth 22161 * linux-firmware: Update firmware file for Intel Bluetooth 9560 * linux-firmware: Update firmware file for Intel Bluetooth 9260 * linux-firmware: Update AMD SEV firmware (CVE-2019-9836, bsc#1139383) * linux-firmware: update licence text for Marvell firmware * linux-firmware: update firmware for mhdp8546 * linux-firmware: rsi: update firmware images for Redpine 9113 chipset * imx: sdma: update firmware to v3.5/v4.5 * nvidia: update GP10[2467] SEC2 RTOS with the one already used on GP108 * linux-firmware: Update firmware file for Intel Bluetooth 8265 * linux-firmware: Update firmware file for Intel Bluetooth 9260 * linux-firmware: Update firmware file for Intel Bluetooth 9560 * amlogic: add video decoder firmwares * iwlwifi: update -46 firmwares for 22260 and 9000 series * iwlwifi: add firmware for 22260 and update 9000 series -46 firmwares * iwlwifi: add -46.ucode firmwares for 9000 series * amdgpu: update vega20 to the latest 19.10 firmware * amdgpu: update vega12 to the latest 19.10 firmware * amdgpu: update vega10 to the latest 19.10 firmware * amdgpu: update polaris11 to the latest 19.10firmware * amdgpu: update polaris10 to the latest 19.10 firmware * amdgpu: update raven2 to the latest 19.10 firmware * amdgpu: update raven to the latest 19.10 firmware * amdgpu: update picasso to the latest 19.10 firmware * linux-firmware: update fw for qat devices * Mellanox: Add new mlxsw_spectrum firmware 13.2000.1122 * drm/i915/firmware: Add ICL HuC v8.4.3238 * drm/i915/firmware: Add ICL GuC v32.0.3 * drm/i915/firmware: Add GLK HuC v03.01.2893 * drm/i915/firmware: Add GLK GuC v32.0.3 * drm/i915/firmware: Add KBL GuC v32.0.3 * drm/i915/firmware: Add SKL GuC v32.0.3 * drm/i915/firmware: Add BXT GuC v32.0.3 * linux-firmware: Add firmware file for Intel Bluetooth 22161 * cxgb4: update firmware to revision 1.23.4.0 (bsc#1136334) * linux-firmware: Update NXP Management Complex firmware to version 10.14.3 * linux-firmware: add firmware for MT7615E * mediatek: update MT8173 VPU firmware to v1.1.2 [decoder] Enlarge struct vdec_pic_info to support more capture buffer plane and capture buffer format change. * linux-firmware: update Marvell 8797/8997 firmware images * nfp: update Agilio SmartNIC flower firmware to rev AOTC-2.10.A.23 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-1803=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (noarch): kernel-firmware-20190618-3.22.1 ucode-amd-20190618-3.22.1 References: https://www.suse.com/security/cve/CVE-2019-9836.html https://bugzilla.suse.com/1136334 https://bugzilla.suse.com/1136498 https://bugzilla.suse.com/1139383 _______________________________________________ sle-security-updates mailinglist
Microcode update for AMD cpus. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c4670f2981 2018-01-09 15:17:15.724000 --------------------------------------------------------------------------------Name : linux-firmware Product : Fedora 26 Version : 20171215 Release : 82.git2451bb22.fc26 URL : https://www.kernel.org/ Summary : Firmware files used by the Linux kernel Description : This package includes firmware files required for some devices to operate. --------------------------------------------------------------------------------Update Information: Microcode update for AMD cpus --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade linux-firmware' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.