Synopsis: Important: linux-firmware security update
Advisory ID: SLSA-2018:0014-1
Issue Date: 2018-01-04
CVE Numbers: CVE-2017-5715
—
Security Fix(es):
* An industry-wide issue was found in the way many modern microprocessor
designs have implemented speculative execution of instructions (a commonly
used performance optimization). There are three primary variants of the
issue which differ in the way the speculative execution can be exploited.
Variant CVE-2017-5715 triggers the speculative execution by utilizing
branch target injection. It relies on the presence of a precisely-defined
instruction sequence in the privileged code as well as the fact that
memory accesses may cause allocation into the microprocessor’s data cache
even for speculatively executed instructions that never actually commit
(retire). As a result, an unprivileged attacker could use this flaw to
cross the syscall and guest/host boundaries and read privileged memory by
conducting targeted cache side-channel attacks. (CVE-2017-5715)
Note: This is the microcode counterpart of the CVE-2017-5715 kernel
mitigation.
—
SL7
noarch
iwl100-firmware-39.31.5.1-57.el7_4.noarch.rpm
iwl1000-firmware-39.31.5.1-57.el7_4.noarch.rpm
iwl105-firmware-18.168.6.1-57.el7_4.noarch.rpm
iwl135-firmware-18.168.6.1-57.el7_4.noarch.rpm
iwl2000-firmware-18.168.6.1-57.el7_4.noarch.rpm
iwl2030-firmware-18.168.6.1-57.el7_4.noarch.rpm
iwl3160-firmware-22.0.7.0-57.el7_4.noarch.rpm
iwl3945-firmware-15.32.2.9-57.el7_4.noarch.rpm
iwl4965-firmware-228.61.2.24-57.el7_4.noarch.rpm
iwl5000-firmware-8.83.5.1_1-57.el7_4.noarch.rpm
iwl5150-firmware-8.24.2.2-57.el7_4.noarch.rpm
iwl6000-firmware-9.221.4.1-57.el7_4.noarch.rpm
iwl6000g2a-firmware-17.168.5.3-57.el7_4.noarch.rpm
iwl6000g2b-firmware-17.168.5.2-57.el7_4.noarch.rpm
iwl6050-firmware-41.28.5.1-57.el7_4.noarch.rpm
iwl7260-firmware-22.0.7.0-57.el7_4.noarch.rpm
iwl7265-firmware-22.0.7.0-57.el7_4.noarch.rpm
linux-firmware-20170606-57.gitc990aae.el7_4.noarch.rpm
– Scientific Linux Development Team