Mageia 2022-0065: nonfree firmware security update
Summary
This update provides new and updated nonfree firmwares and fixes atleast
the following security issues:
Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi
may allow an unauthenticated user to potentially enable escalation of
privilege via local access (CVE-2021-0066 / SA-00539).
Improper input validation in firmware for some Intel(R) PROSet/Wireless
Wi-Fi may allow a privileged user to potentially enable information
disclosure via local access (CVE-2021-0072 / SA-00539).
Improper Validation of Specified Index, Position, or Offset in Input in
firmware for some Intel(R) PROSet/Wireless Wi-Fi may allow a privileged
user to potentially enable denial of service via local access
(CVE-2021-0076 / SA-00539).
Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi
may allow a privileged user to potentially enable escalation of privilege
via local access (CVE-2021-0161, CVE-2021-0168 / SA-00539).
Improper access control in firmware for Intel(R) PROSet/Wi...
References
- https://bugs.mageia.org/show_bug.cgi?id=30038
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00539.html
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00604.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0066
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0072
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0076
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0161
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0164
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0165
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0166
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0168
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0170
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0172
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0173
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0174
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0175
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-0176
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33139
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33155
Resolution
MGASA-2022-0065 - Updated nonfree firmware packages fix security vulnerabilities
SRPMS
- 8/nonfree/kernel-firmware-nonfree-20220209-1.mga8.nonfree
- 8/nonfree/radeon-firmware-20220209-1.mga8.nonfree