QID 239534
Date Published: 2021-08-16
QID 239534: Red Hat Update for microcode_ctl (RHSA-2021:3028)
The microcode_ctl packages provide microcode updates for Intel.
Security Fix(es): hw: Special Register Buffer Data Sampling (SRBDS)
(CVE-2020-0543)
hw: Vector Register Data Sampling (CVE-2020-0548)
hw: L1D Cache Eviction Sampling (CVE-2020-0549)
hw: vt-d related privilege escalation (CVE-2020-24489)
hw: improper isolation of shared resources in some Intel Processors (CVE-2020-24511)
hw: observable timing discrepancy in some Intel Processors (CVE-2020-24512)
hw: Information disclosure issue in Intel SGX via RAPL interface (CVE-2020-8695)
hw: Vector Register Leakage-Active (CVE-2020-8696)
hw: Fast forward store predictor (CVE-2020-8698)
Solution
Before applying this update, make sure all previously released erratarelevant to your system have been applied.For details on how to apply this update, refer to:https://access.redhat.com/articles/11258
Affected Products
Red Hat Enterprise Linux Server 7 x86_64
Red Hat Enterprise Linux Workstation 7 x86_64
Red Hat Enterprise Linux Desktop 7 x86_64
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
Fixes
BZ - 1788786
- CVE-2020-0548 hw: Vector Register Data Sampling
BZ - 1788788
- CVE-2020-0549 hw: L1D Cache Eviction Sampling
BZ - 1827165
- CVE-2020-0543 hw: Special Register Buffer Data Sampling (SRBDS)
BZ - 1828583
- CVE-2020-8695 hw: Information disclosure issue in Intel SGX via RAPL interface
BZ - 1890355
- CVE-2020-8696 hw: Vector Register Leakage-Active
BZ - 1890356
- CVE-2020-8698 hw: Fast forward store predictor
BZ - 1897684
- [rhel-7.9.z] Re-enable 06-5e-03 (SKL-H/S, CPUID 0x506e3)
latest microcode updates
BZ - 1962650
- CVE-2020-24489 hw: vt-d related privilege escalation
BZ - 1962702
- CVE-2020-24511 hw: improper isolation of shared resources in some Intel Processors
BZ - 1962722
- CVE-2020-24512 hw: observable timing discrepancy in some Intel Processors
CVEs
CVE-2020-0543
CVE-2020-0548
CVE-2020-0549
CVE-2020-8695
CVE-2020-8696
CVE-2020-8698
CVE-2020-24489
CVE-2020-24511
CVE-2020-24512
References
https://access.redhat.com/security/updates/classification/#important
Note:
More recent versions of these packages may be available.
Click a package name
Affected Products:
Red Hat Enterprise Linux Server 7 x86_64
Red Hat Enterprise Linux Workstation 7 x86_64
Red Hat Enterprise Linux Desktop 7 x86_64
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
On successful exploitation, it could allow an attacker to execute code.
Refer to Red Hat security advisory RHSA-2021:3028 to address this issue and obtain more information.
- RHSA-2021:3028 -
access.redhat.com/errata/RHSA-2021:3028?language=en
CVEs related to QID 239534
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| RHSA-2021:3028 | Red Hat Enterprise Linux |
|