MGASA-2020-0298

Source
https://advisories.mageia.org/MGASA-2020-0298.html
Import Source
https://advisories.mageia.org/MGASA-2020-0298.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0298
Related
Published
2020-07-31T23:25:42Z
Modified
2020-07-31T22:41:28Z
Summary
Updated microcode packages fix security vulnerability
Details

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0543)

Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0548)

Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-0549)

References
Credits

Affected packages

Mageia:7 / microcode

Package

Name
microcode
Purl
pkg:rpm/mageia/microcode?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.20200616-1.mga7.nonfree

Ecosystem specific

{
    "section": "nonfree"
}