Updated microcode packages fix security vulnerabilities
Publication date: 13 Jan 2018Modification date: 14 Mar 2018
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-5715
Description
This update provides microcode fixes and mitigations for Spectre (CVE-2017-5715) for many Intel CPUs produced in the last 5 years. So far the Intel microcode updates are for several processors from the Haswell, Broadwell, Skylake, Kaby Lake, Coffee Lake, Gemini Lake, Apollo Lake, Crystal Well and IVT platforms We also have added the latest known microcode for Amd family 17 (Zen) processors. We will provide more microcode updates when they are made available by Intel and Amd. We also suggest that you check if there is updated BIOS and EFI firmwares from your hardware vendor.
References
- https://bugs.mageia.org/show_bug.cgi?id=22337
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr
- https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File?product=52214
- http://www.amd.com/en/corporate/speculative-execution
- https://meltdownattack.com/
- https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715
SRPMS
6/nonfree
- microcode-0.20180108-1.mga6.nonfree
5/nonfree
- microcode-0.20180108-1.mga5.nonfree