Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:0454-1

Опубликовано: 20 фев. 2023
Источник: suse-cvrf

Описание

Security update for ucode-intel

This update for ucode-intel fixes the following issues:

Updated to Intel CPU Microcode 20230214 release.

Security issues fixed:

  • CVE-2022-38090: Security updates for INTEL-SA-00767 (bsc#1208275)

  • CVE-2022-33196: Security updates for INTEL-SA-00738 (bsc#1208276)

  • CVE-2022-21216: Security updates for INTEL-SA-00700 (bsc#1208277)

  • New Platforms:

    ProcessorSteppingF-M-S/PIOld VerNew VerProducts
    SPR-SPE206-8f-05/872b000181Xeon Scalable Gen4
    SPR-SPE306-8f-06/872b000181Xeon Scalable Gen4
    SPR-SPE406-8f-07/872b000181Xeon Scalable Gen4
    SPR-SPE506-8f-08/872b000181Xeon Scalable Gen4
    SPR-HBMB306-8f-08/102c000170Xeon Max
    RPL-P 6+8J006-ba-02/070000410eCore Gen13
    RPL-H 6+8J006-ba-02/070000410eCore Gen13
    RPL-U 2+8Q006-ba-02/070000410eCore Gen13
  • Updated Platforms:

    ProcessorSteppingF-M-S/PIOld VerNew VerProducts
    ADLC006-97-02/07000000260000002cCore Gen12
    ADLC006-97-05/07000000260000002cCore Gen12
    ADLC006-bf-02/07000000260000002cCore Gen12
    ADLC006-bf-05/07000000260000002cCore Gen12
    ADLL006-9a-03/800000042400000429Core Gen12
    ADLL006-9a-04/800000042400000429Core Gen12
    CLX-SPB006-55-06/bf0400330204003303Xeon Scalable Gen2
    CLX-SPB106-55-07/bf0500330205003303Xeon Scalable Gen2
    CPX-SPA106-55-0b/bf0700250107002503Xeon Scalable Gen3
    GLKB006-7a-01/010000003c0000003ePentium Silver N/J5xxx, Celeron N/J4xxx
    GLK-RR006-7a-08/010000002000000022Pentium J5040/N5030, Celeron J4125/J4025/N4020/N4120
    ICL-DB006-6c-01/100100020101000211Xeon D-17xx, D-27xx
    ICL-U/YD106-7e-05/80000000b6000000b8Core Gen10 Mobile
    ICX-SPD006-6a-06/870d0003750d000389Xeon Scalable Gen3
    JSLA0/A106-9c-00/012400002324000024Pentium N6000/N6005, Celeron N4500/N4505/N5100/N5105
    LKFB2/B306-8a-01/100000003100000032Core w/Hybrid Technology
    RKL-SB006-a7-01/020000005600000057Core Gen11
    RPL-SS006-b7-01/320000010e00000112Core Gen13
    SKX-SPB106-55-03/970100015e01000161Xeon Scalable

Список пакетов

Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
ucode-intel-20230214-150100.3.217.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise Server 15 SP1-LTSS
ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
ucode-intel-20230214-150100.3.217.1

Описание

Insufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a privileged user to potentially enable escalation of privilege via adjacent network access.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:ucode-intel-20230214-150100.3.217.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise Server 15 SP1-LTSS:ucode-intel-20230214-150100.3.217.1

Ссылки

Описание

Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:ucode-intel-20230214-150100.3.217.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise Server 15 SP1-LTSS:ucode-intel-20230214-150100.3.217.1

Ссылки

Описание

Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:ucode-intel-20230214-150100.3.217.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:ucode-intel-20230214-150100.3.217.1
SUSE Linux Enterprise Server 15 SP1-LTSS:ucode-intel-20230214-150100.3.217.1

Ссылки
Уязвимость SUSE-SU-2023:0454-1