Debian Package Tracker
Register | Log in
Subscribe

amd64-microcode

Platform firmware and microcode for AMD CPUs and SoCs

Choose email to subscribe with

general
  • source: amd64-microcode (non-free-firmware)
  • version: 3.20250311.1
  • maintainer: Henrique de Moraes Holschuh (DMD)
  • uploaders: Giacomo Catenazzi [DMD]
  • arch: amd64 i386 x32
  • std-ver: 3.9.8
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.20240820.1~deb11u1
  • o-o-sec: 3.20250311.1~deb11u1
  • o-o-p-u: 3.20240820.1~deb11u1
  • oldstable: 3.20250311.1~deb12u1
  • old-sec: 3.20230719.1~deb12u1
  • stable: 3.20250311.1
  • testing: 3.20250311.1
  • unstable: 3.20250311.1
versioned links
  • 3.20230719.1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.20240820.1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.20250311.1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.20250311.1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.20250311.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • amd64-microcode (11 bugs: 0, 10, 1, 0)
action needed
5 security issues in trixie high

There are 5 open security issues in trixie.

4 important issues:
  • CVE-2025-0033: Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.
  • CVE-2024-36350: A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
  • CVE-2024-36357: A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
  • CVE-2025-29934: A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.
1 ignored issue:
  • CVE-2025-62626: Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
Created: 2025-07-08 Last update: 2025-11-24 12:30
5 security issues in sid high

There are 5 open security issues in sid.

5 important issues:
  • CVE-2025-0033: Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.
  • CVE-2024-36350: A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
  • CVE-2024-36357: A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
  • CVE-2025-29934: A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.
  • CVE-2025-62626: Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
Created: 2025-07-08 Last update: 2025-11-24 12:30
5 security issues in forky high

There are 5 open security issues in forky.

5 important issues:
  • CVE-2025-0033: Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.
  • CVE-2024-36350: A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
  • CVE-2024-36357: A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
  • CVE-2025-29934: A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.
  • CVE-2025-62626: Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
Created: 2025-08-09 Last update: 2025-11-24 12:30
5 security issues in bullseye high

There are 5 open security issues in bullseye.

5 important issues:
  • CVE-2025-0033: Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.
  • CVE-2024-36350: A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
  • CVE-2024-36357: A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
  • CVE-2025-29934: A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.
  • CVE-2025-62626: Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
Created: 2025-07-08 Last update: 2025-11-24 12:30
5 security issues in bookworm high

There are 5 open security issues in bookworm.

4 important issues:
  • CVE-2025-0033: Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.
  • CVE-2024-36350: A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
  • CVE-2024-36357: A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
  • CVE-2025-29934: A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.
1 ignored issue:
  • CVE-2025-62626: Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
Created: 2025-07-08 Last update: 2025-11-24 12:30
Standards version of the package is outdated. high
The package is severely out of date with respect to the Debian Policy. The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 3.9.8).
Created: 2023-05-16 Last update: 2025-03-24 06:30
10 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit d6b1a973a214d9c729be69ea552baabd594a637f
Merge: acdc22d 9949bc4
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Thu Oct 23 21:14:45 2025 -0300

    Merge branch 'topic/upstream-20250729'

commit 9949bc49fa46ad635b5fcfe3d9886b90fd6c1436
Merge: 9dd947f 9c0ab4b
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Thu Oct 23 21:14:15 2025 -0300

    Merge branch 'upstream' into topic/upstream-20250729

commit 9c0ab4ba7982b57d5e082de2823abffd73e901fa
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Thu Oct 23 21:13:27 2025 -0300

    README: update with new commit entry

commit 1bcbad1991f66a2a951cb22fca7df7c326293ecd
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Thu Oct 23 20:45:19 2025 -0300

    amd-ucode: add documentation patch from linux-firmware 2025-10-21
    
    commit 3a49a7356a8c83a33d0214edfc5d8fd835caa93a
    Author: Andrew Cooper <andrew.cooper3@citrix.com>
    Date:   Tue Oct 21 14:20:56 2025 +0100
    
        amd-ucode: Fix minimum revisions in README
    
        ... to match the minimum revisions stated in the binaries.
    
        Signed-off-by: Andrew Cooper <andrew.cooper3@citrix.com>

commit acdc22d65f9d9ae21112176d467a7521c9025688
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Sun Oct 19 20:44:00 2025 -0300

    initramfs: avoid copying non-microcode data into the early-initramfs
    
    Ensure only microcode_amd*.bin files will be concatenated into the
    early-initramfs microcode data file.  Otherwise, non-microcode data
    files that happen to be present in the firmware source directory will
    corrupt the data stream, and the kernel will most likely fail to find
    the desired microcode update in the resulting mess.
    
    While this doesn't happen when using *only* microcode data from
    unmodified Debian packages, it will happen should the full contents of
    the amd-ucode/ directory from upstream linux-firmware (which contains a
    README and some .asc gnupg signature files) be used as the source of the
    microcode data.
    
    Thanks to Eric Valette for reporting the issue, tracking down the root
    cause, and suggesting a fix.
    
    Reported-by: Eric Valette <eric.valette@free.fr>
    Closes: #1101350

commit c214039cdbc3773415414348619bf46a16b55c46
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Sun Oct 19 19:58:43 2025 -0300

    README: update for new release
    
    Update README with the updated AMD-UCODE release.
    
    Note: this is the first microcode release for AMD processors with the
    new-style microcode signature scheme.
    
    It will NOT work on systems with outdated firmware missing the new-style
    signature support.  Attempting to load these microcode updates on
    systems with the outdated and vulnerable firmware will NOT work: the
    microcode update will be refused by the processor, since it cannot
    understand the new-style signatures.
    
    Refer to AMD-SB-7033 for details:
    https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html

commit 7047840a7e3d7283dfea8d881758e5b7ace5f784
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Sun Oct 19 19:48:06 2025 -0300

    amd-ucode: update amd-ucode to release 2025-07-29
    
    Compose a 20250729 amd-ucode release from linux-firmware
    https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git
    
    commit 3768c184de68a85b9df6697e7f93a2f61de90a99
    Author: John Allen <john.allen@amd.com>
    Date:   Tue Jul 29 10:21:29 2025 -0500
    
        linux-firmware: Update AMD cpu microcode
    
        * Update AMD cpu microcode for processor family 19h
        * Add AMD cpu microcode for processor family 1ah
    
        Key Name        = AMD Microcode Signing Key (for signing microcode
        container files only)
        Key ID          = F328AE73
        Key Fingerprint = FC7C 6C50 5DAF CC14 7183 57CA E4BE 5339 F328 AE73
    
        Signed-off-by: John Allen <john.allen@amd.com>

commit 0fbca5752224df3a37c9c46e1c0a5b50cebb65ac
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Sun Oct 19 19:42:11 2025 -0300

    README: update for new release
    
    Update README with the updated AMD-TEE and AMD-UCODE releases.
    
    Note: this is the final microcode release for AMD processors with the
    old-style microcode signature scheme.
    
    Refer to AMD-SB-7033 for details:
    https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html

commit a7a67b93bc772ab19ca7b2613ec26eb256cc760a
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Sun Oct 19 19:35:01 2025 -0300

    amd-ucode: update amd-ucode to release 2025-07-08
    
    Compose a 20250708 amd-ucode release from linux-firmware
    https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git
    
    commit 331eac9144402d6cfa02ff3b2888a40bb9a7a01a
    Author: John Allen <john.allen@amd.com>
    Date:   Mon Jul 7 18:56:23 2025 +0000
    
        linux-firmware: Update AMD cpu microcode
    
        * Update AMD cpu microcode for processor family 19h
    
        Key Name        = AMD Microcode Signing Key (for signing microcode container files only)
        Key ID          = F328AE73
        Key Fingerprint = FC7C 6C50 5DAF CC14 7183 57CA E4BE 5339 F328 AE73
    
        Signed-off-by: John Allen <john.allen@amd.com>
        Signed-off-by: Josh Boyer <jwboyer@kernel.org>

commit 78c19f88fed257fe97fbb2298ca0cff328e64172
Author: Henrique de Moraes Holschuh <hmh@debian.org>
Date:   Sun Oct 19 19:18:27 2025 -0300

    amd-tee: update AMD PMF TA Firmware to v3.1
    
    Compose a amd-tee release 20250507 from linux-firmware
    https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git
    
    commit 86d528c261657497967cb2b2051374639e6ad476
    Author: Shyam Sundar  S K <shyam-sundar.s-k@amd.com>
    Date:   Wed May 7 14:22:26 2025 +0000
    
        amd_pmf: Update AMD PMF TA Firmware to v3.1
Created: 2025-10-20 Last update: 2025-11-23 22:48
4 open merge requests in Salsa normal
There are 4 open merge requests for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2025-09-22 Last update: 2025-09-22 16:04
lintian reports 2 warnings normal
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-07-21 Last update: 2025-07-21 22:02
news
[rss feed]
  • [2025-06-21] Accepted amd64-microcode 3.20250311.1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • [2025-03-31] Accepted amd64-microcode 3.20250311.1~deb11u1 (source) into oldstable-security (Tobias Frost)
  • [2025-03-29] amd64-microcode 3.20250311.1 MIGRATED to testing (Debian testing watch)
  • [2025-03-24] Accepted amd64-microcode 3.20250311.1 (source) into unstable (Henrique de Moraes Holschuh)
  • [2024-08-24] Accepted amd64-microcode 3.20240820.1~deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • [2024-08-24] Accepted amd64-microcode 3.20240820.1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • [2024-08-24] amd64-microcode 3.20240820.1 MIGRATED to testing (Debian testing watch)
  • [2024-08-24] amd64-microcode 3.20240820.1 MIGRATED to testing (Debian testing watch)
  • [2024-08-22] Accepted amd64-microcode 3.20240820.1 (source) into unstable (Henrique de Moraes Holschuh)
  • [2024-08-21] Accepted amd64-microcode 3.20240710.2~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • [2024-08-21] Accepted amd64-microcode 3.20240710.2~deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • [2024-08-14] amd64-microcode 3.20240710.2 MIGRATED to testing (Debian testing watch)
  • [2024-08-12] Accepted amd64-microcode 3.20240710.2 (source) into unstable (Henrique de Moraes Holschuh)
  • [2024-08-11] Accepted amd64-microcode 3.20240710.1 (source) into unstable (Henrique de Moraes Holschuh)
  • [2024-06-19] amd64-microcode 3.20240116.2+nmu1 MIGRATED to testing (Debian testing watch)
  • [2024-06-13] Accepted amd64-microcode 3.20240116.2+nmu1 (source) into unstable (Chris Hofstaedtler) (signed by: Christian Hofstaedtler)
  • [2024-03-08] amd64-microcode 3.20240116.2 MIGRATED to testing (Debian testing watch)
  • [2024-03-02] Accepted amd64-microcode 3.20240116.2 (source) into unstable (Henrique de Moraes Holschuh)
  • [2023-10-27] amd64-microcode 3.20231019.1 MIGRATED to testing (Debian testing watch)
  • [2023-10-21] Accepted amd64-microcode 3.20231019.1 (source) into unstable (Henrique de Moraes Holschuh)
  • [2023-10-18] amd64-microcode 3.20230823.1 MIGRATED to testing (Debian testing watch)
  • [2023-10-13] Accepted amd64-microcode 3.20230823.1 (source) into unstable (Henrique de Moraes Holschuh)
  • [2023-10-01] Accepted amd64-microcode 3.20230808.1.1~deb11u1 (source amd64) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • [2023-10-01] Accepted amd64-microcode 3.20230808.1.1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • [2023-08-12] amd64-microcode 3.20230808.1.1 MIGRATED to testing (Debian testing watch)
  • [2023-08-10] Accepted amd64-microcode 3.20230808.1.1 (source) into unstable (Henrique de Moraes Holschuh)
  • [2023-08-10] Accepted amd64-microcode 3.20230808.1 (source) into unstable (Henrique de Moraes Holschuh)
  • [2023-07-31] Accepted amd64-microcode 3.20230719.1~deb10u1 (source amd64) into oldoldstable (Jochen Sprickerhof)
  • [2023-07-27] amd64-microcode 3.20230719.1 MIGRATED to testing (Debian testing watch)
  • [2023-07-26] Accepted amd64-microcode 3.20230719.1~deb11u1 (source amd64) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Henrique de Moraes Holschuh)
  • 1
  • 2
bugs [bug history graph]
  • all: 14 15
  • RC: 1
  • I&N: 9 10
  • M&W: 2
  • F&P: 2
  • patch: 0
links
  • lintian (0, 2)
  • buildd: logs, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.20250708.1ubuntu1
  • 3 bugs
  • patches for 3.20250708.1ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing