Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 832985 (CVE-2021-0127, CVE-2021-0146) - <sys-firmware/intel-microcode-20220207_p20220207: Multiple vulnerabilities
Summary: <sys-firmware/intel-microcode-20220207_p20220207: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2021-0127, CVE-2021-0146
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://github.com/intel/Intel-Linux-...
Whiteboard: A3 [glsa+]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-02-09 11:46 UTC by Ian Kumlien
Modified: 2024-02-19 06:13 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ian Kumlien 2022-02-09 11:46:08 UTC
The following issues has been fixed:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00532.html

Reproducible: Always

Actual Results:  
.

Expected Results:  
.

.
Comment 1 Larry the Git Cow gentoo-dev 2022-02-10 02:02:09 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3929b7925d6255539ab40a9d76391c9a39458289

commit 3929b7925d6255539ab40a9d76391c9a39458289
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2022-02-10 01:59:01 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2022-02-10 02:01:40 +0000

    sys-firmware/intel-microcode: bump
    
    - New microcodes:
    
      sig 0x000906a2, pf_mask 0x80, 2022-01-02, rev 0x0315
      sig 0x000906a3, pf_mask 0x80, 2021-12-29, rev 0x0415
      sig 0x000906a4, pf_mask 0x80, 2021-12-29, rev 0x0415
      sig 0x000b0670, pf_mask 0x02, 2021-11-15, rev 0x0009
    
    - Updated microcodes:
    
      sig 0x000206f0, pf_mask 0x05, 2010-06-30, rev 0x0004    -> 2010-07-29, rev 0x0005
      sig 0x000306f2, pf_mask 0x6f, 2021-01-27, rev 0x0046    -> 2021-08-11, rev 0x0049
      sig 0x000306f4, pf_mask 0x80, 2021-02-05, rev 0x0019    -> 2021-05-24, rev 0x001a
      sig 0x000406e3, pf_mask 0xc0, 2021-01-25, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x00050653, pf_mask 0x97, 2021-03-08, rev 0x100015b -> 2021-05-26, rev 0x100015c
      sig 0x00050654, pf_mask 0xb7, 2021-03-08, rev 0x2006b06 -> 2021-06-16, rev 0x2006c0a
      sig 0x00050656, pf_mask 0xbf, 2021-04-20, rev 0x4003103 -> 2021-08-13, rev 0x400320a
      sig 0x00050657, pf_mask 0xbf, 2021-04-08, rev 0x5003103 -> 2021-08-13, rev 0x500320a
      sig 0x0005065b, pf_mask 0xbf, 2021-04-23, rev 0x7002302 -> 2021-06-04, rev 0x7002402
      sig 0x00050663, pf_mask 0x10, 2021-02-04, rev 0x700001b -> 2021-06-12, rev 0x700001c
      sig 0x00050664, pf_mask 0x10, 2021-02-04, rev 0xf000019 -> 2021-06-12, rev 0xf00001a
      sig 0x00050665, pf_mask 0x10, 2021-02-04, rev 0xe000012 -> 2021-09-18, rev 0xe000014
      sig 0x000506c9, pf_mask 0x03, 2020-10-23, rev 0x0044    -> 2021-05-10, rev 0x0046
      sig 0x000506ca, pf_mask 0x03, 2020-10-23, rev 0x0020    -> 2021-05-10, rev 0x0024
      sig 0x000506e3, pf_mask 0x36, 2021-01-25, rev 0x00ea    -> 2021-04-29, rev 0x00ec
      sig 0x000506f1, pf_mask 0x01, 2020-10-23, rev 0x0034    -> 2021-05-10, rev 0x0036
      sig 0x000606a6, pf_mask 0x87, 2021-06-25, rev 0xd0002d0 -> 2021-12-03, rev 0xd000331
      sig 0x000706a1, pf_mask 0x01, 2020-10-23, rev 0x0036    -> 2021-05-10, rev 0x0038
      sig 0x000706a8, pf_mask 0x01, 2020-10-23, rev 0x001a    -> 2021-05-10, rev 0x001c
      sig 0x000706e5, pf_mask 0x80, 2020-11-01, rev 0x00a6    -> 2021-05-26, rev 0x00a8
      sig 0x000806a1, pf_mask 0x10, 2020-11-06, rev 0x002a    -> 2021-09-02, rev 0x002d
      sig 0x000806c1, pf_mask 0x80, 2021-04-09, rev 0x008a    -> 2021-10-26, rev 0x009c
      sig 0x000806c2, pf_mask 0xc2, 2021-04-07, rev 0x0016    -> 2021-07-16, rev 0x0022
      sig 0x000806e9, pf_mask 0xc0, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000806e9, pf_mask 0x10, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000806ea, pf_mask 0xc0, 2021-01-06, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000806eb, pf_mask 0xd0, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000806ec, pf_mask 0x94, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x00090661, pf_mask 0x01, 2021-02-04, rev 0x0011    -> 2021-09-21, rev 0x0015
      sig 0x00090671, pf_mask 0x82, 2021-05-05, rev 0x001a    -> 2021-06-14, rev 0x001c
      sig 0x00090672, pf_mask 0x03, 2021-08-16, rev 0x000d    -> 2022-01-03, rev 0x001a
      sig 0x00090675, pf_mask 0x03, 2021-08-16, rev 0x000d    -> 2022-01-03, rev 0x001a
      sig 0x000906a0, pf_mask 0x82, 2021-05-05, rev 0x001a    -> 2021-06-14, rev 0x001c
      sig 0x000906c0, pf_mask 0x01, 2021-03-23, rev 0x001d    -> 2021-08-09, rev 0x2400001f
      sig 0x000906e9, pf_mask 0x2a, 2021-01-05, rev 0x00ea    -> 2021-04-29, rev 0x00ec
      sig 0x000906ea, pf_mask 0x22, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000906eb, pf_mask 0x02, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000906ec, pf_mask 0x22, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000906ed, pf_mask 0x22, 2021-01-05, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000a0652, pf_mask 0x20, 2021-02-07, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000a0653, pf_mask 0x22, 2021-03-08, rev 0x00ea    -> 2021-04-28, rev 0x00ec
      sig 0x000a0655, pf_mask 0x22, 2021-03-08, rev 0x00ec    -> 2021-04-28, rev 0x00ee
      sig 0x000a0660, pf_mask 0x80, 2020-12-08, rev 0x00e8    -> 2021-04-28, rev 0x00ea
      sig 0x000a0661, pf_mask 0x80, 2021-02-07, rev 0x00ea    -> 2021-04-29, rev 0x00ec
      sig 0x000a0671, pf_mask 0x02, 2021-04-11, rev 0x0040    -> 2021-08-29, rev 0x0050
    
    Bug: https://bugs.gentoo.org/832985
    Package-Manager: Portage-3.0.30, Repoman-3.0.3
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 sys-firmware/intel-microcode/Manifest              |   2 +
 .../intel-microcode-20220207_p20220207.ebuild      | 262 +++++++++++++++++++++
 2 files changed, 264 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2024-02-19 06:10:55 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=62babe5642376fcb1290e16ecd12047d38418a82

commit 62babe5642376fcb1290e16ecd12047d38418a82
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-02-19 05:57:31 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2024-02-19 06:10:22 +0000

    [ GLSA 202402-22 ] intel-microcode: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/832985
    Bug: https://bugs.gentoo.org/894474
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 glsa-202402-22.xml | 44 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 44 insertions(+)