security advisorydebianinformation disclosure
It was discovered that systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (Spectre v2). . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2743-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta August 16, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : amd64-microcode Version : 3.20181128.1~deb9u1 CVE ID : CVE-2017-5715 Debian Bug : 886382 It was discovered that systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis (Spectre v2). Multiple fixes were done already in Linux kernel, intel-microcode, et al. This fix adds amd-microcode-based IBPB support. For Debian 9 stretch, this problem has been fixed in version 3.20181128.1~deb9u1. We recommend that you upgrade your amd64-microcode packages. For the detailed security status of amd64-microcode please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/amd64-microcode Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Discover the essential Debian security patch for amd64-microcode, targeting Spectre v2 vulnerabilities to enhance system safety and user protection against threats. Debian Security, amd64 Microcode Update, Speculative Execution Risk. . LinuxSecurity.com Team
Aug 16, 2021
Debian LTS