Ubuntu has issued an advisory on May 29: https://ubuntu.com/security/notices/USN-6797-1 The issues are fixed upstream in 20240514: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20240514 Mageia 9 is also affected.
Source RPM: (none) => microcode-0.20240312-1.mga10.nonfree.src.rpmCVE: (none) => CVE-2023-45733, CVE-2023-46103, CVE-2023-45745Status comment: (none) => Fixed upstream in 20240514
Whiteboard: (none) => MGA9TOO
CC: (none) => friAssignee: bugsquad => kernel
Suggested advisory: ======================== The updated package fixes security vulnerabilities: Hardware logic contains race conditions in some Intel(R) Processors may allow an authenticated user to potentially enable partial information disclosure via local access. (CVE-2023-45733) Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access. (CVE-2023-46103) Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2023-45745) References: https://ubuntu.com/security/notices/USN-6797-1 https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20240514 ======================== Updated package in core/updates_testing: ======================== microcode-0.20240514-1.mga9.nonfree from SRPM: microcode-0.20240514-1.mga9.nonfree.src.rpm
Source RPM: microcode-0.20240312-1.mga10.nonfree.src.rpm => microcode-0.20240312-1.mga9.nonfree.src.rpmAssignee: kernel => qa-bugsWhiteboard: MGA9TOO => (none)Status: NEW => ASSIGNEDVersion: Cauldron => 9Status comment: Fixed upstream in 20240514 => (none)
Keywords: (none) => advisory
mga9, x64 12-core (4-mt/8-st) 12th Gen Intel Core i7-1260P [MST AMCP] Updated package via qarepo... Reboot. $ sudo journalctl -xb | grep microcode May 30 20:33:34 yildun kernel: microcode: updated early: 0x421 -> 0x433, date = 2023-12-05 May 30 20:33:34 yildun kernel: microcode: Microcode Update Driver: v2.2. Not an Ultra processor so no change.
CC: (none) => tarazed25
mga9-64, old i870 $ sudo journalctl -xb | grep microcode maj 30 20:54:54 svarten.tribun kernel: microcode: updated early: 0x3 -> 0xa, date = 2018-05-08 maj 30 20:54:54 svarten.tribun kernel: MDS: Vulnerable: Clear CPU buffers attempted, no microcode maj 30 20:54:54 svarten.tribun kernel: microcode: Microcode Update Driver: v2.2. $ inxi -c CPU: dual core Intel Core i7 870 (-MT MCP-) speed/min/max: 3407/1200/2934 MHz Kernel: 6.6.28-desktop-1.mga9 x86_64 Up: 4h 56m Mem: 3933.3/15994.3 MiB (24.6%) Storage: 2.27 TiB (81.4% used) Procs: 266 Shell: Bash inxi: 3.3.26 No problem noted during a few hours use.
mga9-64, Thinkpad T510 $ sudo journalctl -xb | grep microcode [sudo] lösenord för ettan: maj 30 11:34:34 localhost kernel: microcode: updated early: 0x3 -> 0x7, date = 2018-04-23 maj 30 11:34:34 localhost kernel: MDS: Vulnerable: Clear CPU buffers attempted, no microcode maj 30 11:34:34 localhost kernel: microcode: Microcode Update Driver: v2.2. $ inxi -c CPU: dual core Intel Core i5 M 540 (-MT MCP-) speed/min/max: 1531/1199/2534 MHz Kernel: 6.6.28-1.mga9 x86_64 Up: 14h 51m Mem: 3855.7/7813.9 MiB (49.3%) Storage: 447.13 GiB (18.2% used) Procs: 338 Shell: Bash inxi: 3.3.26 No problems noted.
RH mageia 9 x86_64 LC_ALL=C urpmi --auto --auto-update medium "QA Testing (64-bit)" is up-to-date medium "Core Release (distrib1)" is up-to-date medium "Core Updates (distrib3)" is up-to-date medium "Nonfree Release (distrib11)" is up-to-date medium "Nonfree Updates (distrib13)" is up-to-date medium "Tainted Release (distrib21)" is up-to-date medium "Tainted Updates (distrib23)" is up-to-date medium "Core 32bit Release (distrib31)" is up-to-date medium "Core 32bit Updates (distrib32)" is up-to-date medium "Nonfree 32bit Release (distrib36)" is up-to-date medium "Tainted 32bit Release (distrib41)" is up-to-date medium "Tainted 32bit Updates (distrib42)" is up-to-date installing microcode-0.20240514-1.mga9.nonfree.noarch.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/1: microcode ################################################################################################## dracut: dracut module 'systemd-initrd' depends on 'systemd', which can't be installed dracut: dracut module 'ifcfg' depends on 'network', which can't be installed dracut: dracut module 'systemd-initrd' depends on 'systemd', which can't be installed dracut: dracut module 'dracut-systemd' depends on 'systemd-initrd', which can't be installed dracut: dracut module 'ifcfg' depends on 'network', which can't be installed 1/1: removing microcode-0.20240312-1.mga9.nonfree.noarch ################################################################################################## journalctl -xb | grep microcode may 30 19:20:25 phoenix kernel: microcode: updated early: 0x2 -> 0x7, date = 2018-04-23 may 30 19:20:25 phoenix kernel: MDS: Vulnerable: Clear CPU buffers attempted, no microcode may 30 19:20:25 phoenix kernel: microcode: Microcode Update Driver: v2.2. Consistent bug#33015 comment#6
RH mageia 9 i586 LC_ALL=C urpmi --auto --auto-update medium "QA Testing (32-bit)" is up-to-date medium "Core Release (distrib1)" is up-to-date medium "Core Updates (distrib3)" is up-to-date medium "Nonfree Release (distrib11)" is up-to-date medium "Nonfree Updates (distrib13)" is up-to-date medium "Tainted Release (distrib21)" is up-to-date medium "Tainted Updates (distrib23)" is up-to-date installing microcode-0.20240514-1.mga9.nonfree.noarch.rpm from //home/katnatek/qa-testing/i586 Preparing... ################################################################ 1/1: microcode ################################################################ dracut: dracut module 'systemd-initrd' depends on 'systemd', which can't be installed dracut: dracut module 'ifcfg' depends on 'network', which can't be installed dracut: dracut module 'systemd-initrd' depends on 'systemd', which can't be installed dracut: dracut module 'dracut-systemd' depends on 'systemd-initrd', which can't be installed dracut: dracut module 'ifcfg' depends on 'network', which can't be installed 1/1: removing microcode-0.20240312-1.mga9.nonfree.noarch ################################################################ journalctl -xb | grep microcode may 30 19:21:28 cefiro kernel: microcode: updated early: 0xa3 -> 0xa4, date = 2010-10-02 may 30 19:21:28 cefiro kernel: MDS: Vulnerable: Clear CPU buffers attempted, no microcode may 30 19:21:29 cefiro kernel: microcode: Microcode Update Driver: v2.2. Consistent bug#33015 comment#7 Note: Obviously I reboot after update and when system finish the load I open session again and proceed to paste the saved result of the update and the journalctl output for both tesy
MGA9-64 Plasma, i5-7500. No installation issues. [root@localhost ~]# journalctl -xb | grep microcode May 30 21:52:12 localhost.localdomain kernel: microcode: updated early: 0xb4 -> 0xf8, date = 2023-09-28 May 30 21:52:12 localhost.localdomain kernel: microcode: Microcode Update Driver: v2.2. [root@localhost ~]# inxi -c CPU: quad core Intel Core i5-7500 (-MCP-) speed/min/max: 1229/800/3800 MHz Kernel: 6.6.28-desktop-1.mga9 x86_64 Up: 2m Mem: 3249.1/48118.6 MiB (6.8%) Storage: 1.84 TiB (26.4% used) Procs: 279 Shell: Bash inxi: 3.3.26 Looks good so far.
CC: (none) => andrewsfarm
urpmi microcode ~ ~ installing microcode-0.20240514-1.mga9.nonfree.noarch.rpm from /var/cache/urpmi/rpms Preparing... ##################################################################################### 1/1: microcode ##################################################################################### dracut: dracut module 'systemd-initrd' depends on 'systemd', which can't be installed dracut: dracut module 'ifcfg' depends on 'network', which can't be installed dracut: dracut module 'systemd-initrd' depends on 'systemd', which can't be installed dracut: dracut module 'dracut-systemd' depends on 'systemd-initrd', which can't be installed dracut: dracut module 'ifcfg' depends on 'network', which can't be installed 1/1: removing microcode-0.20240312-1.mga9.nonfree.noarch ~ reboot to a working system lscpu Architecture: x86_64 Vendor ID: AuthenticAMD Model name: AMD E1-6010 APU with AMD Radeon R2 Graphics
CC: (none) => westel
MGA9-64 Plasma Wayland on HP-Pavillion. No installation issues. Rebooted and all seems OK. $ inxi -c CPU: quad core Intel Pentium N3710 (-MCP-) speed/min/max: 1369/480/2560 MHz Kernel: 6.6.28-server-1.mga9 x86_64 Up: 4m Mem: 1879.0/3771.0 MiB (49.8%) Storage: 465.76 GiB (7.5% used) Procs: 242 Shell: Bash inxi: 3.3.26
CC: (none) => herman.viaene
MGA9-64 Plasma on an HP Pavilion. This one is AMD-based, so probably no affected, but... [root@localhost ~]# journalctl -xb | grep microcode May 31 08:08:35 localhost.localdomain kernel: microcode: microcode updated early to new patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU2: patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU3: patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU0: patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU1: patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU3: new patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU2: new patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU1: new patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: CPU0: new patch_level=0x06001119 May 31 08:08:35 localhost.localdomain kernel: microcode: Microcode Update Driver: v2.2. [root@localhost ~]# inxi -c CPU: quad core AMD A8-4555M APU with Radeon HD Graphics (-MT MCP-) speed/min/max: 1175/1100/1600 MHz Kernel: 6.6.28-desktop-1.mga9 x86_64 Up: 3m Mem: 2057.3/15192.6 MiB (13.5%) Storage: 942.7 GiB (26.5% used) Procs: 223 Shell: Bash inxi: 3.3.26 Looks good here.
Older i7 system $ inxi -C CPU: Info: quad core model: Intel Core i7-7700K bits: 64 type: MT MCP cache: L2: 1024 KiB Speed (MHz): avg: 800 min/max: 800/4500 cores: 1: 800 2: 800 3: 800 4: 800 5: 800 6: 800 7: 800 8: 800 microcode update uneventful and all seems OK on re-boot
CC: (none) => tablackwell
MGA9-64 two different AMD systems Ryzen 5600 and 3015i installation didn't kill them.
CC: (none) => brtians1
Enough tests. Validating.
CC: (none) => sysadmin-bugsWhiteboard: (none) => MGA9-64-OK MGA9-32-OKKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0207.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED