-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 27 Jan 2019 13:07:47 -0200 Source: intel-microcode Binary: intel-microcode Architecture: amd64 i386 source Version: 3.20180807a.2~deb9u1 Distribution: stretch Urgency: medium Maintainer: Henrique de Moraes Holschuh <hmh@debian.org> Changed-By: Henrique de Moraes Holschuh <hmh@debian.org> Closes: 907402 Description: intel-microcode - Processor microcode firmware for Intel CPUs Changes: intel-microcode (3.20180807a.2~deb9u1) stretch; urgency=medium . * Release managers: This update is being distributed by Debian in unstable, testing and jessie- and stretch-backports since 2018-10-30 without issues, and by most distros since 2018-08/2018-09, with no known reports of regressions on Westmere EP processors (Spectre mitigations are very expensive on Nehalem and Westmere, though). * SECURITY FIX: this update adds the accumulated fixes for Westmere EP (signature 0x206c2) from nearly a decade, including but likely not limited to: + Implements L1D_FLUSH support (L1TF "Foreshadow/-NG" mitigation) Intel SA-00161, CVE-2018-3615, CVE-2018-3620, CVE-2018-3646 + Implements SSBD support (Spectre v4 mitigation), Disable speculation for (some) RDMSR/WRMSR (Spectre v3a fix) Intel SA-00115, CVE-2018-3639, CVE-2018-3640 + Implements IBRS/IBPB/STIPB support, Spectre v2 mitigation. Intel SA-0088, CVE-2017-5753, CVE-2017-5754 + Very likely implements LAPIC sinkhole fix + Fixes AAK167/BT248: Virtual APIC accesses with 32-bit PAE paging may cause system crash * This Westmere EP microcode update has been explicitly approved by Intel for general distribution by operating systems, refer to the changelog entry for 3.20180807a.2 below . intel-microcode (3.20180807a.2) unstable; urgency=medium . * Makefile: unblacklist 0x206c2 (Westmere EP) According to pragyansri.pathi@intel.com, on message to LP#1795594 on 2018-10-09, we can ship 0x206c2 updates without restrictions. Also, there are no reports in the field about this update causing issues (closes: #907402) (LP: #1795594) Checksums-Sha1: b11b6b8c15a33d8e1b20e5de434bc05cac97ed1e 1817 intel-microcode_3.20180807a.2~deb9u1.dsc f3b2eb8a198f9d0e34c9c0113666476a4c096289 1984816 intel-microcode_3.20180807a.2~deb9u1.tar.xz 53387e46df49e5b049d20bb4e502535b6979f1e1 6015 intel-microcode_3.20180807a.2~deb9u1_amd64.buildinfo cd77a7428d9698e2fabff057206220cafcbefe00 1306466 intel-microcode_3.20180807a.2~deb9u1_amd64.deb 5fadda705fcf3eb53fcc39039c2af04f39077338 4778 intel-microcode_3.20180807a.2~deb9u1_i386.buildinfo 87008fd1bc4c68a072c0f653a5749bbd1147824e 1445214 intel-microcode_3.20180807a.2~deb9u1_i386.deb Checksums-Sha256: 7e458c589a299b8e18efb0cbcc00a76a03a21e2e9b9ae09d847c05feee7bb15f 1817 intel-microcode_3.20180807a.2~deb9u1.dsc 8d763283ff4385d30e619a854f63a39cb875048a596873b0ad2fd4e0d7a6dbf8 1984816 intel-microcode_3.20180807a.2~deb9u1.tar.xz 88dcc82cde5927790b0e087f62b0eb19dfd4f3700c82abb58d33bb813fbcd3f2 6015 intel-microcode_3.20180807a.2~deb9u1_amd64.buildinfo 379ed270de49d9b813339094f275714b21e04c6b69dd566750106990b958334d 1306466 intel-microcode_3.20180807a.2~deb9u1_amd64.deb f081f17702d956d515d61ebfd64366e40310b397fe7b892519cdfaf35b139a01 4778 intel-microcode_3.20180807a.2~deb9u1_i386.buildinfo 571fd1acbe3634babfd4a58c803f08ecb7045bfa86a64989a60c757fb4dc728e 1445214 intel-microcode_3.20180807a.2~deb9u1_i386.deb Files: c9b515ac6c903e3320a43217c28747c7 1817 non-free/admin standard intel-microcode_3.20180807a.2~deb9u1.dsc 9e3d368f8bab558345268e28f5782966 1984816 non-free/admin standard intel-microcode_3.20180807a.2~deb9u1.tar.xz 9167044db2e55c11d09f326007f2a107 6015 non-free/admin standard intel-microcode_3.20180807a.2~deb9u1_amd64.buildinfo 91ba29d7cb1bd8d8a901280fa04ea50b 1306466 non-free/admin standard intel-microcode_3.20180807a.2~deb9u1_amd64.deb ea38bdfed4288e5fa4ea9b049f8a1626 4778 non-free/admin standard intel-microcode_3.20180807a.2~deb9u1_i386.buildinfo edbdfa71aeb0972d64759fb44cbb7be6 1445214 non-free/admin standard intel-microcode_3.20180807a.2~deb9u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEMr8sdJFqJgkTTH+qsZwaZk2P+bEFAlxasgoACgkQsZwaZk2P +bGhWBAAnQw7GA9kJMN5sHojYOz6EMQczTsrFo14A1NL/72B5slt7d4bLSZdBd73 N17yu5bJpBWgVi1hOVgJ7S3JgIESRhPdygtgETfAxRFLwrW9OP8odl0xYAMkB7cb zPYzFnqOdv/qtTeLDruVFz7ryPYOUiJ4lw5hkWv/WQcMTjuBIuzyUXl+CUdUzaVr C1tQVKnLoUZXG/3lJ7S0WU7J1e/Zr61RMlMJDoFhhlKVJouZUrmd39aEAoDhWemF Ryrh/GjDFgMtgcAytmxDQQX/3wa86T54cDLD6e1Bz25koT15zTQTXlDkpoHun9qM aRXPcLIsClkkVDC7CF8mki2JVhtZIr9o8Sgy6WI/lAvJmSdomjRHL7lXtIKt0sy9 N7zxXx+6oUBE86wukeCOakU+zFAQYw3vL+7iljxE+van8WJIYsPeQ/lPvX2NAlUn IC8TAdes2Gld8eDnKPOSML/rSwYtLgHcnukoqDSDqjSRD5y3IBK7X1Bwy/pf2SwX kppd4tofsgguI2v0a06hX1T+zMjjvBUxf9KkG0ehDz7ROl74/0rQSB5M30eRM2c6 iEa/Mx9OiW9J0sTeVQILYmPIWtrgY5Y0tsWGoZtDIQyAsreqoH4fItZcorK+dleH P51I4gVJUq0pdvYuYAc7UpRYi30ImjGkEJGchdeV9GWmicVYo2g= =1wdE -----END PGP SIGNATURE-----