{"id":"openSUSE-SU-2020:0791-1","summary":"Security update for ucode-intel","details":"This update for ucode-intel fixes the following issues:\n\nUpdated Intel CPU Microcode to 20200602 (prerelease) (bsc#1172466)\n  \nThis update contains security mitigations for:\n\n- CVE-2020-0543: Fixed a side channel attack against special registers\n  which could have resulted in leaking of read values to cores other\n  than the one which called it.  This attack is known as Special Register\n  Buffer Data Sampling (SRBDS) or 'CrossTalk' (bsc#1154824).\n- CVE-2020-0548,CVE-2020-0549: Additional ucode updates were supplied to\n  mitigate the Vector Register and L1D Eviction Sampling aka 'CacheOutAttack'\n  attacks. (bsc#1156353)\n\nMicrocode Table:\n\n  Processor             Identifier     Version       Products\n  Model        Stepping F-MO-S/PI      Old-\u003eNew\n  ---- new platforms ----------------------------------------\n  ---- updated platforms ------------------------------------\n  HSW          C0       6-3c-3/32 00000027-\u003e00000028 Core Gen4\n  BDW-U/Y      E0/F0    6-3d-4/c0 0000002e-\u003e0000002f Core Gen5\n  HSW-U        C0/D0    6-45-1/72 00000025-\u003e00000026 Core Gen4\n  HSW-H        C0       6-46-1/32 0000001b-\u003e0000001c Core Gen4\n  BDW-H/E3     E0/G0    6-47-1/22 00000021-\u003e00000022 Core Gen5\n  SKL-U/Y      D0       6-4e-3/c0 000000d6-\u003e000000dc Core Gen6 Mobile\n  SKL-U23e     K1       6-4e-3/c0 000000d6-\u003e000000dc Core Gen6 Mobile\n  SKX-SP       B1       6-55-3/97 01000151-\u003e01000157 Xeon Scalable\n  SKX-SP       H0/M0/U0 6-55-4/b7 02000065-\u003e02006906 Xeon Scalable\n  SKX-D        M1       6-55-4/b7 02000065-\u003e02006906 Xeon D-21xx\n  CLX-SP       B0       6-55-6/bf 0400002c-\u003e04002f01 Xeon Scalable Gen2\n  CLX-SP       B1       6-55-7/bf 0500002c-\u003e04002f01 Xeon Scalable Gen2\n  SKL-H/S      R0/N0    6-5e-3/36 000000d6-\u003e000000dc Core Gen6; Xeon E3 v5\n  AML-Y22      H0       6-8e-9/10 000000ca-\u003e000000d6 Core Gen8 Mobile\n  KBL-U/Y      H0       6-8e-9/c0 000000ca-\u003e000000d6 Core Gen7 Mobile\n  CFL-U43e     D0       6-8e-a/c0 000000ca-\u003e000000d6 Core Gen8 Mobile\n  WHL-U        W0       6-8e-b/d0 000000ca-\u003e000000d6 Core Gen8 Mobile\n  AML-Y42      V0       6-8e-c/94 000000ca-\u003e000000d6 Core Gen10 Mobile\n  CML-Y42      V0       6-8e-c/94 000000ca-\u003e000000d6 Core Gen10 Mobile\n  WHL-U        V0       6-8e-c/94 000000ca-\u003e000000d6 Core Gen8 Mobile\n  KBL-G/H/S/E3 B0       6-9e-9/2a 000000ca-\u003e000000d6 Core Gen7; Xeon E3 v6\n  CFL-H/S/E3   U0       6-9e-a/22 000000ca-\u003e000000d6 Core Gen8 Desktop, Mobile, Xeon E\n  CFL-S        B0       6-9e-b/02 000000ca-\u003e000000d6 Core Gen8\n  CFL-H/S      P0       6-9e-c/22 000000ca-\u003e000000d6 Core Gen9\n  CFL-H        R0       6-9e-d/22 000000ca-\u003e000000d6 Core Gen9 Mobile\n\nAlso contains the Intel CPU Microcode update to 20200520:\n\n  Processor             Identifier     Version       Products\n  Model        Stepping F-MO-S/PI      Old-\u003eNew\n  ---- new platforms ----------------------------------------\n  ---- updated platforms ------------------------------------\n  SNB-E/EN/EP  C1/M0    6-2d-6/6d 0000061f-\u003e00000621 Xeon E3/E5, Core X\n  SNB-E/EN/EP  C2/M1    6-2d-7/6d 00000718-\u003e0000071a Xeon E3/E5, Core X\n\nThis update was imported from the SUSE:SLE-15-SP1:Update update project.","modified":"2026-03-11T07:32:30.797023Z","published":"2020-06-10T17:58:41Z","related":["CVE-2020-0543","CVE-2020-0548","CVE-2020-0549"],"upstream":["CVE-2020-0543","CVE-2020-0548","CVE-2020-0549"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FEGYVZIAZERXLY4SF7SWJUPJOF7CD7LU/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154824"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156353"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-0543"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-0548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-0549"}],"affected":[{"package":{"name":"ucode-intel","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/ucode-intel&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20200602-lp151.2.24.1"}]}],"ecosystem_specific":{"binaries":[{"ucode-intel":"20200602-lp151.2.24.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0791-1.json"}}],"schema_version":"1.7.5"}