-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 13 Jun 2020 10:27:53 -0300 Binary: intel-microcode Source: intel-microcode Architecture: amd64 i386 source Version: 3.20200609.2~deb8u1 Distribution: jessie-security Urgency: high Maintainer: Henrique de Moraes Holschuh <hmh@debian.org> Changed-By: Henrique de Moraes Holschuh <hmh@debian.org> Description: intel-microcode - Processor microcode firmware for Intel CPUs Changes: intel-microcode (3.20200609.2~deb8u1) jessie-security; urgency=high . * Rebuild for jessie-security, no changes Refer to changelog entries for 3.20200609.2 and 3.20200609.1 for details . intel-microcode (3.20200609.2) unstable; urgency=medium . * REGRESSION FIX: 0x406e3: rollback to rev 0xd6 and document regression * Microcode rollbacks (closes: LP#1883002) sig 0x000406e3, pf_mask 0xc0, 2019-10-03, rev 0x00d6, size 101376 * THIS REMOVES THE SECURITY FIXES FOR SKYLAKE-U/Y PROCESSORS * Avoid hangs on boot on (some?) Skylake-U/Y processors, https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/31 * ucode-blacklist: blacklist models 0x8e and 0x9e from late-loading, just in case. Note that Debian does not do late loading by itself. Refer to LP#1883002 for the report, 0x806ec hangs upon late load. . intel-microcode (3.20200609.1) unstable; urgency=high . * SECURITY UPDATE * For most processors: SRBDS and/or VRDS, L1DCES mitigations depending on the processor model * For Skylake HEDT and Skylake Xeons with signature 0x50654: VRDS and L1DCES mitigations, plus mitigations described in the changelog entry for package release 3.20191112.1. * Expect some performance impact, the mitigations are enabled by default. A Linux kernel update will be issued that allows one to selectively disable the mitigations. * New upstream microcode datafile 20200609 * Implements mitigation for CVE-2020-0543 Special Register Buffer Data Sampling (SRBDS), INTEL-SA-00320, CROSSTalk * Implements mitigation for CVE-2020-0548 Vector Register Data Sampling (VRDS), INTEL-SA-00329 * Implements mitigation for CVE-2020-0549 L1D Cache Eviction Sampling (L1DCES), INTEL-SA-00329 * Known to fix the regression introduced in release 2019-11-12 (sig 0x50564, rev. 0x2000065), which would cause several systems with Skylake Xeon, Skylake HEDT processors to hang while rebooting * Updated Microcodes: sig 0x000306c3, pf_mask 0x32, 2019-11-12, rev 0x0028, size 23552 sig 0x000306d4, pf_mask 0xc0, 2019-11-12, rev 0x002f, size 19456 sig 0x00040651, pf_mask 0x72, 2019-11-12, rev 0x0026, size 22528 sig 0x00040661, pf_mask 0x32, 2019-11-12, rev 0x001c, size 25600 sig 0x00040671, pf_mask 0x22, 2019-11-12, rev 0x0022, size 14336 sig 0x000406e3, pf_mask 0xc0, 2020-04-27, rev 0x00dc, size 104448 sig 0x00050653, pf_mask 0x97, 2020-04-24, rev 0x1000157, size 32768 sig 0x00050654, pf_mask 0xb7, 2020-04-24, rev 0x2006906, size 34816 sig 0x00050656, pf_mask 0xbf, 2020-04-23, rev 0x4002f01, size 52224 sig 0x00050657, pf_mask 0xbf, 2020-04-23, rev 0x5002f01, size 52224 sig 0x000506e3, pf_mask 0x36, 2020-04-27, rev 0x00dc, size 104448 sig 0x000806e9, pf_mask 0x10, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806e9, pf_mask 0xc0, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806ea, pf_mask 0xc0, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806eb, pf_mask 0xd0, 2020-04-27, rev 0x00d6, size 103424 sig 0x000806ec, pf_mask 0x94, 2020-04-23, rev 0x00d6, size 103424 sig 0x000906e9, pf_mask 0x2a, 2020-04-23, rev 0x00d6, size 103424 sig 0x000906ea, pf_mask 0x22, 2020-04-27, rev 0x00d6, size 102400 sig 0x000906eb, pf_mask 0x02, 2020-04-23, rev 0x00d6, size 103424 sig 0x000906ec, pf_mask 0x22, 2020-04-27, rev 0x00d6, size 102400 sig 0x000906ed, pf_mask 0x22, 2020-04-23, rev 0x00d6, size 103424 * Restores the microcode-level fixes that were reverted by release 3.20191115.2 for sig 0x50654 (Skylake Xeon, Skylake HEDT) . intel-microcode (3.20200520.1) unstable; urgency=medium . * New upstream microcode datafile 20200520 + Updated Microcodes: sig 0x000206d6, pf_mask 0x6d, 2020-03-04, rev 0x0621, size 18432 sig 0x000206d7, pf_mask 0x6d, 2020-03-24, rev 0x071a, size 19456 . intel-microcode (3.20200508.1) unstable; urgency=medium . * New upstream microcode datafile 20200508 + Updated Microcodes: sig 0x000706e5, pf_mask 0x80, 2020-03-12, rev 0x0078, size 107520 * Likely fixes several critical errata on IceLake-U/Y causing system hangs Checksums-Sha1: 7dee7c79459f76ae86ad010eb4c63ecc38c2cad8 1817 intel-microcode_3.20200609.2~deb8u1.dsc f5e2a87043a7fa2edee0e855e65bdeba1e59b9d5 3254228 intel-microcode_3.20200609.2~deb8u1.tar.xz 02f387483d69ef7bffcb1535d46f61e7a8872388 2547312 intel-microcode_3.20200609.2~deb8u1_amd64.deb b0f2fd8ff1a726f6605a1e3eb1465cdaece3e16f 2687978 intel-microcode_3.20200609.2~deb8u1_i386.deb Checksums-Sha256: cb747d128dc46cdf4b6ce80f5de3601bc15939027ab40cf57dc84cac8dd9d491 1817 intel-microcode_3.20200609.2~deb8u1.dsc 432f71473114c46181128dd59180861b0e8fa870edc4625d7321551a706ffaf5 3254228 intel-microcode_3.20200609.2~deb8u1.tar.xz a229bde7dd83d892adac21adf38096958d851fef8c0ae3bfcb041276adb6dd91 2547312 intel-microcode_3.20200609.2~deb8u1_amd64.deb d6e1de729db27e8441c81d2e134be676e760132ba502aa3f2af0fffe0284d841 2687978 intel-microcode_3.20200609.2~deb8u1_i386.deb Files: 8450774df392657b4398c2aedc621326 1817 non-free/admin standard intel-microcode_3.20200609.2~deb8u1.dsc 73dacf646ea5c687a5c1a3741b4a6fda 3254228 non-free/admin standard intel-microcode_3.20200609.2~deb8u1.tar.xz 79079c34f219c159481384fdaadd25b7 2547312 non-free/admin standard intel-microcode_3.20200609.2~deb8u1_amd64.deb 1302e93ffdaf729b17f360a35d88b075 2687978 non-free/admin standard intel-microcode_3.20200609.2~deb8u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQWtPby40keG61F/9KC7xu6bDcIUFAl7k1gsACgkQKC7xu6bD cIWuKw/9FG6Ht9UYpsp9uAVDwuZP5AOf2NPTQ/BrAO8ctlvbCaC1xQlbFNrQb2Si q3pbSnKBAYajIdVzPDeQz0sb4QndU67OUKVHQU+vvNmNUYO0IQM6oM6gTYs4wa+m 1D88TSdnDfm62iaiUuCV43Jcv8MXzgQ/KFiWRBzYBRzlGIuSTumLcM0AB/cOQe6p Po4tR0TL0YcjVcRDriAMUZSXCjgA3uzYPUvC1nUOJwbNB6bNn13/RsrR2bJr/sFc iQiSiaPo2p9Dm5UMLYuoVuoS9cokXUI0eqSjo6JY+mam0N6U1XvQ+/I1+JeBHH5g fqqOw5TBvTMGqEtC9TzYEOPxHoJtc9JcgtGJeFjQvV8MuSQE0W2NYlgH2Mbv4KD3 oLzJDCSVweuzAjdujxqHVBE2s7QEkMSon9raFYvxf3pga5oY8r2En0R1LzJDFpO6 DKgcB7IyJhN8C/LP5DRUs7bGrFYtUi2YLqC8ZrTXg4qBu/QJFeQo6mcuRvBMTQMb oCytAY4hXv8sj/VJwa51ou+1uYEKAKFFFgcLJa1SnlBSwnzZ1b8zYnD1hSvLss7M ZLCvGMgm9B+qNPWKibAV1N3krH3G5Rbe8VVeP3twQ8Nvmu1z8NTfiu9/3B5whU+Q 0tymUbJze/tVvjmZ62LgG1Aty19Kkm2FtyifgZeIphbP2EUqXr4= =2Nq+ -----END PGP SIGNATURE-----