Oval Definition:oval:com.redhat.rhsa:def:20180014
Revision Date:2018-01-04Version:633
Title:RHSA-2018:0014: linux-firmware security update (Important)
Description:The linux-firmware packages contain all of the firmware files that are required by various devices to operate.

Security Fix(es):

  • An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited. Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks. (CVE-2017-5715)

    Note: This is the microcode counterpart of the CVE-2017-5715 kernel mitigation.

    Red Hat would like to thank Google Project Zero for reporting this issue.
  • Family:unixClass:patch
    Status:Reference(s):RHSA-2018:0014
    RHSA-2018:0014-00
    RHSA-2018:0014-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • iwl100-firmware is earlier than 0:39.31.5.1-57.el7_4
  • AND iwl100-firmware is signed with Red Hat redhatrelease2 key
  • iwl1000-firmware is earlier than 1:39.31.5.1-57.el7_4
  • AND iwl1000-firmware is signed with Red Hat redhatrelease2 key
  • iwl105-firmware is earlier than 0:18.168.6.1-57.el7_4
  • AND iwl105-firmware is signed with Red Hat redhatrelease2 key
  • iwl135-firmware is earlier than 0:18.168.6.1-57.el7_4
  • AND iwl135-firmware is signed with Red Hat redhatrelease2 key
  • iwl2000-firmware is earlier than 0:18.168.6.1-57.el7_4
  • AND iwl2000-firmware is signed with Red Hat redhatrelease2 key
  • iwl2030-firmware is earlier than 0:18.168.6.1-57.el7_4
  • AND iwl2030-firmware is signed with Red Hat redhatrelease2 key
  • iwl3160-firmware is earlier than 0:22.0.7.0-57.el7_4
  • AND iwl3160-firmware is signed with Red Hat redhatrelease2 key
  • iwl3945-firmware is earlier than 0:15.32.2.9-57.el7_4
  • AND iwl3945-firmware is signed with Red Hat redhatrelease2 key
  • iwl4965-firmware is earlier than 0:228.61.2.24-57.el7_4
  • AND iwl4965-firmware is signed with Red Hat redhatrelease2 key
  • iwl5000-firmware is earlier than 0:8.83.5.1_1-57.el7_4
  • AND iwl5000-firmware is signed with Red Hat redhatrelease2 key
  • iwl5150-firmware is earlier than 0:8.24.2.2-57.el7_4
  • AND iwl5150-firmware is signed with Red Hat redhatrelease2 key
  • iwl6000-firmware is earlier than 0:9.221.4.1-57.el7_4
  • AND iwl6000-firmware is signed with Red Hat redhatrelease2 key
  • iwl6000g2a-firmware is earlier than 0:17.168.5.3-57.el7_4
  • AND iwl6000g2a-firmware is signed with Red Hat redhatrelease2 key
  • iwl6000g2b-firmware is earlier than 0:17.168.5.2-57.el7_4
  • AND iwl6000g2b-firmware is signed with Red Hat redhatrelease2 key
  • iwl6050-firmware is earlier than 0:41.28.5.1-57.el7_4
  • AND iwl6050-firmware is signed with Red Hat redhatrelease2 key
  • iwl7260-firmware is earlier than 0:22.0.7.0-57.el7_4
  • AND iwl7260-firmware is signed with Red Hat redhatrelease2 key
  • iwl7265-firmware is earlier than 0:22.0.7.0-57.el7_4
  • AND iwl7265-firmware is signed with Red Hat redhatrelease2 key
  • linux-firmware is earlier than 0:20170606-57.gitc990aae.el7_4
  • AND linux-firmware is signed with Red Hat redhatrelease2 key
  • BACK