Mageia 2019-0172: kernel-linus security update
Summary
This kernel update provides the upstream 4.14.119 that adds the kernel side
mitigations for the Microarchitectural Data Sampling (MDS, also called
ZombieLoad attack) vulnerabilities in Intel processors that can allow
attackers to retrieve data being processed inside a CPU. To complete the
mitigations new microcode is also needed, either by installing the
microcode-0.20190514-1.mga6 package, or get an updated bios / uefi
firmware from the motherboard vendor.
The fixed / mitigated issues are:
Modern Intel microprocessors implement hardware-level micro-optimizations
to improve the performance of writing data back to CPU caches. The write
operation is split into STA (STore Address) and STD (STore Data)
sub-operations. These sub-operations allow the processor to hand-off
address generation logic into these sub-operations for optimized writes.
Both of these sub-operations write to a shared distributed processor
structure called the 'processor store buffer'. As a result, an
unprivileged at...
References
- https://bugs.mageia.org/show_bug.cgi?id=24775
- https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.101
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.102
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.103
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.104
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.105
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.106
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.107
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.108
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.109
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.110
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.111
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.112
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.113
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.115
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.116
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.117
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.118
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.119
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12126
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12127
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12130
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000026
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3882
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7308
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9213
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11091
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11486
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11599
Resolution
MGASA-2019-0172 - Updated kernel-linus packages fixes security vulnerabilities
SRPMS
- 6/core/kernel-linus-4.14.119-1.mga6