Bug 23062 - Update request: microcode-0.20180425-1.mga6.nonfree
Summary: Update request: microcode-0.20180425-1.mga6.nonfree
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard:
Keywords: advisory, validated_update
Depends on:
Blocks: 23075 23076 23077
  Show dependency treegraph
 
Reported: 2018-05-19 22:19 CEST by Thomas Backlund
Modified: 2018-05-29 21:42 CEST (History)
6 users (show)

See Also:
Source RPM: microcode
CVE:
Status comment:


Attachments

Description Thomas Backlund 2018-05-19 22:19:49 CEST
Intel refreshed their microcode update to add spectre/meltdown fixes for:
- Pentium Silver N/J5xxx, Celeron N/J4xxx
- Xeon E5/E7 v4; Core i7-69xx/68xx


Amd released updated microcode for Fam15 and Fam17 cpus that should have spectre  fixes...


SRPM / RPM:

microcode-0.20180425-1.mga6.nonfree
Thomas Backlund 2018-05-23 09:27:53 CEST

Blocks: (none) => 23075

Thomas Backlund 2018-05-23 09:28:01 CEST

Blocks: (none) => 23076

Thomas Backlund 2018-05-23 09:28:09 CEST

Blocks: (none) => 23077

Comment 1 Len Lawrence 2018-05-23 11:43:20 CEST
Installed OK on this Core i7-4790 nvidia system.
Kernel: 4.14.43-1.mga6 x86_64

Everything works still.

CC: (none) => tarazed25

Comment 2 Morgan Leijström 2018-05-23 13:33:21 CEST
No noticed breakage here

64 bit OK with kernel-desktop 4.14.40,42,43 on my workstation, CPU i7-2600K, with all updates in testing; nvidia-current, virtualbox with MSW7, LVM on LUKS

64 bit OK with kernel-desktop 4.14.43 on laptop Thinkpad T60, CPU core2Duo T5600, ati RV515/M54 X1400, wifi AR5418, LVM on LUKS, with all updates in testing.

CC: (none) => fri

Comment 3 Thomas Andrews 2018-05-24 02:18:08 CEST
Updated my HP 6550b, with the i3 350M processor, executed a "dracut -f" and did a cold boot. As expected, this CPU was unaffected by this update, but on the plus side nothing seems to be broken that wasn't broken before.

I have not yet tested it with the 4.14.43 kernel, as I am waiting for the virtualbox kmods to be built.

CC: (none) => andrewsfarm

Comment 4 Thomas Andrews 2018-05-24 02:53:43 CEST
Wouldn't you know it? my Athlon X2 7759 is family 16. Oh, well, I updated the microcode anyway, executed a "dracut -f" and did a cold boot.

As expected, this processor was unaffected, but, nothing appears to be broken.
Comment 5 James Kerr 2018-05-24 06:38:47 CEST
on mga6-64

package installed cleanly:
microcode-0.20180425-1.mga6.nonfree.noarch

executed dracut -f
re-booted

no regressions noted

looks OK on this system:

Machine:   Device: desktop System: Dell product: Precision Tower 3620
           Mobo: Dell model: 09WH54 v: A00 UEFI [Legacy]
           Dell v: 2.7.3 date: 01/31/2018
CPU:       Quad core Intel Core i7-6700 (-HT-MCP-)

CC: (none) => jim

Comment 6 José Jorge 2018-05-27 09:06:44 CEST
Tested on Arrandale i3-450M. Still not concerned, even if Intel told in April they updated microcode for this hardware. Ref : https://www.theregister.co.uk/2018/04/04/intel_spectre_microcode_updates/

Tested on 2016 Celeron N2830, no microcode update too...

CC: (none) => lists.jjorge

Comment 7 Thomas Backlund 2018-05-29 19:55:35 CEST
validating as it blocks kernel update and has also been in cauldron for ~2 weeks

Advisory, added to svn

type: security
subject: Updated microcode packages fix security vulnerability
CVE:
 - CVE-2017-5715
src:
  6:
   nonfree:
     - microcode-0.20180425-1.mga6.nonfree
description: |
  This update adds microcode fixes and mitigations for Spectre
  (CVE-2017-5715) for the following:

  Intel Pentium Silver N/J5xxx, Celeron N/J4xxx
  Intel Xeon E5/E7 v4; Core i7-69xx/68xx

  Amd has also released their updated microcode for Fam15 and Fam17 cpus
references:
 - https://bugs.mageia.org/show_bug.cgi?id=23062

Keywords: (none) => advisory, validated_update
CC: (none) => sysadmin-bugs

Comment 8 Mageia Robot 2018-05-29 21:42:33 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0260.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.