Print

Print


Synopsis:          Important: linux-firmware security update
Advisory ID:       SLSA-2018:0014-1
Issue Date:        2018-01-04
CVE Numbers:       CVE-2017-5715
--

Security Fix(es):

* An industry-wide issue was found in the way many modern microprocessor
designs have implemented speculative execution of instructions (a commonly
used performance optimization). There are three primary variants of the
issue which differ in the way the speculative execution can be exploited.
Variant CVE-2017-5715 triggers the speculative execution by utilizing
branch target injection. It relies on the presence of a precisely-defined
instruction sequence in the privileged code as well as the fact that
memory accesses may cause allocation into the microprocessor's data cache
even for speculatively executed instructions that never actually commit
(retire). As a result, an unprivileged attacker could use this flaw to
cross the syscall and guest/host boundaries and read privileged memory by
conducting targeted cache side-channel attacks. (CVE-2017-5715)

Note: This is the microcode counterpart of the CVE-2017-5715 kernel
mitigation.
--

SL7
  noarch
    iwl100-firmware-39.31.5.1-57.el7_4.noarch.rpm
    iwl1000-firmware-39.31.5.1-57.el7_4.noarch.rpm
    iwl105-firmware-18.168.6.1-57.el7_4.noarch.rpm
    iwl135-firmware-18.168.6.1-57.el7_4.noarch.rpm
    iwl2000-firmware-18.168.6.1-57.el7_4.noarch.rpm
    iwl2030-firmware-18.168.6.1-57.el7_4.noarch.rpm
    iwl3160-firmware-22.0.7.0-57.el7_4.noarch.rpm
    iwl3945-firmware-15.32.2.9-57.el7_4.noarch.rpm
    iwl4965-firmware-228.61.2.24-57.el7_4.noarch.rpm
    iwl5000-firmware-8.83.5.1_1-57.el7_4.noarch.rpm
    iwl5150-firmware-8.24.2.2-57.el7_4.noarch.rpm
    iwl6000-firmware-9.221.4.1-57.el7_4.noarch.rpm
    iwl6000g2a-firmware-17.168.5.3-57.el7_4.noarch.rpm
    iwl6000g2b-firmware-17.168.5.2-57.el7_4.noarch.rpm
    iwl6050-firmware-41.28.5.1-57.el7_4.noarch.rpm
    iwl7260-firmware-22.0.7.0-57.el7_4.noarch.rpm
    iwl7265-firmware-22.0.7.0-57.el7_4.noarch.rpm
    linux-firmware-20170606-57.gitc990aae.el7_4.noarch.rpm

- Scientific Linux Development Team