-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 11 Jun 2020 09:29:13 -0300 Binary: intel-microcode Source: intel-microcode Architecture: amd64 i386 source Version: 3.20200609.2~deb9u1 Distribution: stretch-security Urgency: high Maintainer: Henrique de Moraes Holschuh <hmh@debian.org> Changed-By: Henrique de Moraes Holschuh <hmh@debian.org> Description: intel-microcode - Processor microcode firmware for Intel CPUs Changes: intel-microcode (3.20200609.2~deb9u1) stretch-security; urgency=high . * Rebuild for stretch-security, no changes Refer to changelog entries for 3.20200609.2 and 3.20200609.1 for details . intel-microcode (3.20200609.2) unstable; urgency=medium . * REGRESSION FIX: 0x406e3: rollback to rev 0xd6 and document regression * Microcode rollbacks (closes: LP#1883002) sig 0x000406e3, pf_mask 0xc0, 2019-10-03, rev 0x00d6, size 101376 * THIS REMOVES THE SECURITY FIXES FOR SKYLAKE-U/Y PROCESSORS * Avoid hangs on boot on (some?) Skylake-U/Y processors, https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/31 * ucode-blacklist: blacklist models 0x8e and 0x9e from late-loading, just in case. Note that Debian does not do late loading by itself. Refer to LP#1883002 for the report, 0x806ec hangs upon late load. . intel-microcode (3.20200609.1) unstable; urgency=high . * SECURITY UPDATE * For most processors: SRBDS and/or VRDS, L1DCES mitigations depending on the processor model * For Skylake HEDT and Skylake Xeons with signature 0x50654: VRDS and L1DCES mitigations, plus mitigations described in the changelog entry for package release 3.20191112.1. * Expect some performance impact, the mitigations are enabled by default. A Linux kernel update will be issued that allows one to selectively disable the mitigations. * New upstream microcode datafile 20200609 * Implements mitigation for CVE-2020-0543 Special Register Buffer Data Sampling (SRBDS), INTEL-SA-00320, CROSSTalk * Implements mitigation for CVE-2020-0548 Vector Register Data Sampling (VRDS), INTEL-SA-00329 * Implements mitigation for CVE-2020-0549 L1D Cache Eviction Sampling (L1DCES), INTEL-SA-00329 * Known to fix the regression introduced in release 2019-11-12 (sig 0x50564, rev. 0x2000065), which would cause several systems with Skylake Xeon, Skylake HEDT processors to hang while rebooting * Updated Microcodes: sig 0x000306c3, pf_mask 0x32, 2019-11-12, rev 0x0028, size 23552 sig 0x000306d4, pf_mask 0xc0, 2019-11-12, rev 0x002f, size 19456 sig 0x00040651, pf_mask 0x72, 2019-11-12, rev 0x0026, size 22528 sig 0x00040661, pf_mask 0x32, 2019-11-12, rev 0x001c, size 25600 sig 0x00040671, pf_mask 0x22, 2019-11-12, rev 0x0022, size 14336 sig 0x000406e3, pf_mask 0xc0, 2020-04-27, rev 0x00dc, size 104448 sig 0x00050653, pf_mask 0x97, 2020-04-24, rev 0x1000157, size 32768 sig 0x00050654, pf_mask 0xb7, 2020-04-24, rev 0x2006906, size 34816 sig 0x00050656, pf_mask 0xbf, 2020-04-23, rev 0x4002f01, size 52224 sig 0x00050657, pf_mask 0xbf, 2020-04-23, rev 0x5002f01, size 52224 sig 0x000506e3, pf_mask 0x36, 2020-04-27, rev 0x00dc, size 104448 sig 0x000806e9, pf_mask 0x10, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806e9, pf_mask 0xc0, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806ea, pf_mask 0xc0, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806eb, pf_mask 0xd0, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806ec, pf_mask 0x94, 2020-04-23, rev 0x00d6, size 103424 sig 0x000906e9, pf_mask 0x2a, 2020-04-23, rev 0x00d6, size 103424 sig 0x000906ea, pf_mask 0x22, 2020-04-27, rev 0x00d6, size 102400 sig 0x000906eb, pf_mask 0x02, 2020-04-23, rev 0x00d6, size 103424 sig 0x000906ec, pf_mask 0x22, 2020-04-27, rev 0x00d6, size 102400 sig 0x000906ed, pf_mask 0x22, 2020-04-23, rev 0x00d6, size 103424 * Restores the microcode-level fixes that were reverted by release 3.20191115.2 for sig 0x50654 (Skylake Xeon, Skylake HEDT) . intel-microcode (3.20200520.1) unstable; urgency=medium . * New upstream microcode datafile 20200520 + Updated Microcodes: sig 0x000206d6, pf_mask 0x6d, 2020-03-04, rev 0x0621, size 18432 sig 0x000206d7, pf_mask 0x6d, 2020-03-24, rev 0x071a, size 19456 . intel-microcode (3.20200508.1) unstable; urgency=medium . * New upstream microcode datafile 20200508 + Updated Microcodes: sig 0x000706e5, pf_mask 0x80, 2020-03-12, rev 0x0078, size 107520 * Likely fixes several critical errata on IceLake-U/Y causing system hangs Checksums-Sha1: e5ca414ddc1ecdf8a1ca933ea3f1a4aa7b5465f6 1817 intel-microcode_3.20200609.2~deb9u1.dsc 87c8f92d589c967f8af334152c7841e4af72e3a0 3247724 intel-microcode_3.20200609.2~deb9u1.tar.xz 5ca2f4e162e5fbe44b49560f2b0a21db403d91cf 6073 intel-microcode_3.20200609.2~deb9u1_amd64.buildinfo d47dc85d9ddaaa01de3d2afc837994021929d5ca 2548116 intel-microcode_3.20200609.2~deb9u1_amd64.deb 6b5792e4ca2544012226198865aab114cf2534a9 4839 intel-microcode_3.20200609.2~deb9u1_i386.buildinfo 7866936ac6b94edb6e5a26ff0e19817db73be14d 2685846 intel-microcode_3.20200609.2~deb9u1_i386.deb Checksums-Sha256: 5f5e71c9c4a0a9b90373c07f91cf0287e074d00fb50ba18b2f9700b5538c7b4b 1817 intel-microcode_3.20200609.2~deb9u1.dsc 9c24d4ece7876b964e53126c5ccc802bf994aead1e78b68016109eb5c16829cc 3247724 intel-microcode_3.20200609.2~deb9u1.tar.xz c9477fbad02b04a6a37044028ed27a6db5371514e6c986814a081c4c1ea40881 6073 intel-microcode_3.20200609.2~deb9u1_amd64.buildinfo ff59ae0265c50d78978e138a031419e3e4ba85c43e204fd17bb603aa1cd8d6fa 2548116 intel-microcode_3.20200609.2~deb9u1_amd64.deb 0155e9ed50942e10ef6699f96338ca808d78a2a5e578ca67b613d12096a16bdf 4839 intel-microcode_3.20200609.2~deb9u1_i386.buildinfo 38542d368d9103e1467b435626146ef2b286e3c14aa0d7d1099827556bb9a6d3 2685846 intel-microcode_3.20200609.2~deb9u1_i386.deb Files: 32ecd5ff8eb578fd9ccd063c17cc7e1c 1817 non-free/admin standard intel-microcode_3.20200609.2~deb9u1.dsc 1c8340f5f12885336de5303838319026 3247724 non-free/admin standard intel-microcode_3.20200609.2~deb9u1.tar.xz a61bd7bb69dfdd088ab6b0a8879efc9b 6073 non-free/admin standard intel-microcode_3.20200609.2~deb9u1_amd64.buildinfo 9fbc58445f7c8641fe779f134157718b 2548116 non-free/admin standard intel-microcode_3.20200609.2~deb9u1_amd64.deb 87f086d42fc209a31b453595fe6be308 4839 non-free/admin standard intel-microcode_3.20200609.2~deb9u1_i386.buildinfo 08266c454f7cd3e7025c0940e2761dc4 2685846 non-free/admin standard intel-microcode_3.20200609.2~deb9u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQWtPby40keG61F/9KC7xu6bDcIUFAl7iJ1MACgkQKC7xu6bD cIUPcBAAz18eEV9m4Coumtcy7XsRb6BcdwbEC7hgoFx1c4gwIHDhjbpnH8meYiSF qxNuIEG4u0yJrFzPo2h1oRsqzslchTWtS+I+O9kcCrIlNk5GLSg9YZpDw36S+E/p 5D5dlzMC0St5nQIZCo4c/NbMjAw8EgHPcG+7VRNjHBtxBjdT8nFyFbvmjIr1T0yv ccYvQm/E/DHIDPIWkaMW0u5u0L3Pv8sWWYXLqjWOxsp/AoV13MQEuaWMWvU1pMx/ /dmbPc7wSz7RZfSLfWVSIOnLtTFxYeObCiGoBzbYZ+8J1nwPWK7M7wByWcuRov+s 6gfm+cXDh0S6h4I+PbM9GrjZ8oVjKKW9NUaybcjoyXNYdEGZW0wSd4XvFZ9vl1la DGHg8On+Vug/7INAhi09HKNQ2T0Rq3lXJu7IGk0xZf3Ly/wR7PALTKFncTOquGtx JczvfQVdDk6bkO0nIoK03wGZMeEX14Vc7dMDy9v+UpCCkzzvokSd9U4ybBMgWbwK UEsJZzl+8tPybtLuuVon+tCj2YQ06ZW6UjgUuH/HzQZ3J/pK3+qZ6LGZjZ2gVE96 1C3S/ThgGJR763HG1zXsqHFte9aOgghfUuEDZ09rgZLBd/56LMoHb6KfeTzZVVv/ Nxbwjc59y2n8OPb65M3tRHJcfStcoXw6Gh4G0VtRu5WDpzogQwg= =NhoW -----END PGP SIGNATURE-----