{"id":"MGASA-2023-0242","summary":"Updated kernel packages fix security vulnerability","details":"This kernel update is based on upstream 5.15.122 and fixes atleast\nthe following security issue:\n\nUnder specific microarchitectural circumstances, a register in \"Zen 2\"\nCPUs may not be written to 0 correctly. This may cause data from another\nprocess and/or thread to be stored in the YMM register, which may allow\nan attacker to potentially access sensitive information (CVE-2023-20593,\nalso known as Zenbleed)\n\nThis update adds a kernel-side mitigation for this issue to protect users\nuntil Amd gets their fixed microcode / AGESA updates out for all affected\nCPUs. The fixed microcode for Amd EPYC gen2 is available in the\nmicrocode-0.20230613-2.mga8.nonfree package. For other affected CPUs, see\nthe referenced amd.com url that has info about estimated microcode update\ntimelines for various CPUs.\n\nFor other upstream fixes in this update, see the referenced changelogs.\n","modified":"2026-04-16T00:08:51.776948916Z","published":"2023-07-26T22:07:49Z","upstream":["CVE-2023-20593"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0242.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32139"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.121"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.122"},{"type":"WEB","url":"https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7008.html"}],"affected":[{"package":{"name":"kernel","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kernel?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.122-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0242.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.10-1.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0242.json"}},{"package":{"name":"kmod-xtables-addons","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kmod-xtables-addons?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.23-1.23.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0242.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}