Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-5068

Опубликовано: 24 окт. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-5068: linux-firmware security update (MODERATE)

[20230516-999.27.git6c9e0ed5.el9]

  • Update firmware for qat_4xxx devices (Orabug: 35811008)

[20230516-999.26.git6c9e0ed5.el9]

  • Run dracut -f in %posttrans instead of %post (Orabug: 35661938)
  • Drop latest AMD microcode commits to family 19 file to include Milan microcode but not Genoa (Orabug: 35708511)

[20230516-999.25.git6c9e0ed5.el9]

  • Add missing amd-ucode/ files to nano and core rpm (Orabug: 35642190)
  • Add posttrans scriptlet to reload microcode on AMD (Orabug: 35636951)
  • Recreate initramfs for AMD systems (Orabug: 35636951)

[20230516-999.24.git6c9e0ed5.el7]

  • 8a07fa49 linux-firmware: Update AMD fam19h cpu microcode (Orabug: 35659485)

[20230516-999.23.git6c9e0ed5.el9]

  • Firmware files need to be uncompressed for early kernel load to work
  • Resolves Zenbleed (Orabug: 35650345) {CVE-2023-20593}

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

iwl100-firmware

39.31.5.1-999.27.el9

iwl1000-firmware

39.31.5.1-999.27.el9

iwl105-firmware

18.168.6.1-999.27.el9

iwl135-firmware

18.168.6.1-999.27.el9

iwl2000-firmware

18.168.6.1-999.27.el9

iwl2030-firmware

18.168.6.1-999.27.el9

iwl3160-firmware

25.30.13.0-999.27.el9

iwl3945-firmware

15.32.2.9-999.27.el9

iwl4965-firmware

228.61.2.24-999.27.el9

iwl5000-firmware

8.83.5.1_1-999.27.el9

iwl5150-firmware

8.24.2.2-999.27.el9

iwl6000-firmware

9.221.4.1-999.27.el9

iwl6000g2a-firmware

18.168.6.1-999.27.el9

iwl6000g2b-firmware

18.168.6.1-999.27.el9

iwl6050-firmware

41.28.5.1-999.27.el9

iwl7260-firmware

25.30.13.0-999.27.el9

iwlax2xx-firmware

20230516-999.27.el9

libertas-sd8686-firmware

20230516-999.27.git6c9e0ed5.el9

libertas-sd8787-firmware

20230516-999.27.git6c9e0ed5.el9

libertas-usb8388-firmware

20230516-999.27.git6c9e0ed5.el9

libertas-usb8388-olpc-firmware

20230516-999.27.git6c9e0ed5.el9

linux-firmware

20230516-999.27.git6c9e0ed5.el9

linux-firmware-core

20230516-999.27.git6c9e0ed5.el9

linux-firmware-whence

20230516-999.27.git6c9e0ed5.el9

liquidio-firmware

20230516-999.27.git6c9e0ed5.el9

netronome-firmware

20230516-999.27.git6c9e0ed5.el9

Oracle Linux x86_64

iwl100-firmware

39.31.5.1-999.27.el9

iwl1000-firmware

39.31.5.1-999.27.el9

iwl105-firmware

18.168.6.1-999.27.el9

iwl135-firmware

18.168.6.1-999.27.el9

iwl2000-firmware

18.168.6.1-999.27.el9

iwl2030-firmware

18.168.6.1-999.27.el9

iwl3160-firmware

25.30.13.0-999.27.el9

iwl3945-firmware

15.32.2.9-999.27.el9

iwl4965-firmware

228.61.2.24-999.27.el9

iwl5000-firmware

8.83.5.1_1-999.27.el9

iwl5150-firmware

8.24.2.2-999.27.el9

iwl6000-firmware

9.221.4.1-999.27.el9

iwl6000g2a-firmware

18.168.6.1-999.27.el9

iwl6000g2b-firmware

18.168.6.1-999.27.el9

iwl6050-firmware

41.28.5.1-999.27.el9

iwl7260-firmware

25.30.13.0-999.27.el9

iwlax2xx-firmware

20230516-999.27.el9

libertas-sd8686-firmware

20230516-999.27.git6c9e0ed5.el9

libertas-sd8787-firmware

20230516-999.27.git6c9e0ed5.el9

libertas-usb8388-firmware

20230516-999.27.git6c9e0ed5.el9

libertas-usb8388-olpc-firmware

20230516-999.27.git6c9e0ed5.el9

linux-firmware

20230516-999.27.git6c9e0ed5.el9

linux-firmware-core

20230516-999.27.git6c9e0ed5.el9

linux-firmware-whence

20230516-999.27.git6c9e0ed5.el9

liquidio-firmware

20230516-999.27.git6c9e0ed5.el9

netronome-firmware

20230516-999.27.git6c9e0ed5.el9

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVSS3: 6.5
redhat
почти 2 года назад

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVSS3: 5.5
nvd
почти 2 года назад

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVSS3: 5.5
debian
почти 2 года назад

An issue in \u201cZen 2\u201d CPUs, under specific microarchitectural ...

suse-cvrf
больше 1 года назад

Security update for spectre-meltdown-checker