Mageia 2020-0298: microcode security update
Summary
Incomplete cleanup from specific special register read operations in some
Intel(R) Processors may allow an authenticated user to potentially enable
information disclosure via local access. (CVE-2020-0543)
Cleanup errors in some Intel(R) Processors may allow an authenticated user
to potentially enable information disclosure via local access.
(CVE-2020-0548)
Cleanup errors in some data cache evictions for some Intel(R) Processorsmay allow an authenticated user to potentially enable information
disclosure via local access. (CVE-2020-0549)
References
- https://bugs.mageia.org/show_bug.cgi?id=26783
- https://www.debian.org/security/2020/dsa-4701
- https://access.redhat.com/errata/RHSA-2020:2431
- https://ubuntu.com/security/notices/USN-4385-1
- https://ubuntu.com/security/notices/USN-4385-2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/T5OUM24ZC43G4IDT3JUCIHJTSDXJSK6Y/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0543
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0548
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0549
Resolution
MGASA-2020-0298 - Updated microcode packages fix security vulnerability
SRPMS
- 7/nonfree/microcode-0.20200616-1.mga7.nonfree