Accepted intel-microcode 3.20201118.1~deb10u1 (amd64 i386 source) into proposed-updates->stable-new, proposed-updates
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 23 Jan 2021 20:21:54 -0300
Binary: intel-microcode
Source: intel-microcode
Architecture: amd64 i386 source
Version: 3.20201118.1~deb10u1
Distribution: buster
Urgency: high
Maintainer: Henrique de Moraes Holschuh <hmh@debian.org>
Changed-By: Henrique de Moraes Holschuh <hmh@debian.org>
Closes: 974533
Description:
intel-microcode - Processor microcode firmware for Intel CPUs
Changes:
intel-microcode (3.20201118.1~deb10u1) buster; urgency=high
.
* Rebuild for buster, with changes to avoid regressions
* Stable Release Manager: this intel-microcode update *keeps the same
revision* of Skylake D0/R0 microcode updates already in Debian 10; they're
"downgraded" from the point of view of intel-microcode 3.20201118.1.
For these two processor models, an attempt to update to revisions 0xd8
and higher can hang the system should the system firmware have a microcode
revision older than 0x80 -- and revision 0x72/0x74/0x76 apparently are
common enough in the field to ensure many users are affected.
Refer to:
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/31
* Downgraded microcodes (to upstream release 20200616):
sig 0x000406e3, pf_mask 0xc0, 2019-10-03, rev 0x00d6, size 101376
sig 0x000506e3, pf_mask 0x36, 2019-10-03, rev 0x00d6, size 101376
.
intel-microcode (3.20201118.1) unstable; urgency=medium
.
* New upstream microcode datafile 20201118
* Removes a faulty microcode update from release 2020-11-10 for Tiger Lake
processors. Note that Debian already had removed this specific falty
microcode update on the 3.20201110.1 release
* Add a microcode update for the Pentium Silver N/J5xxx and Celeron
N/J4xxx which didn't make it to release 20201110, fixing security issues
(INTEL-SA-00381, INTEL-SA-00389)
* Updated Microcodes:
sig 0x000706a1, pf_mask 0x01, 2020-06-09, rev 0x0034, size 74752
* Removed Microcodes:
sig 0x000806c1, pf_mask 0x80, 2020-10-02, rev 0x0068, size 107520
.
intel-microcode (3.20201110.1) unstable; urgency=medium
.
* New upstream microcode datafile 20201110 (closes: #974533)
* Implements mitigation for CVE-2020-8696 and CVE-2020-8698,
aka INTEL-SA-00381: AVX register information leakage;
Fast-Forward store predictor information leakage
* Implements mitigation for CVE-2020-8695, Intel SGX information
disclosure via RAPL, aka INTEL-SA-00389
* Fixes critical errata on several processor models
* Reintroduces SRBDS mitigations(CVE-2020-0543, INTEL-SA-00320)
for Skylake-U/Y, Skylake Xeon E3
* New Microcodes
sig 0x0005065b, pf_mask 0xbf, 2020-08-20, rev 0x700001e, size 27648
sig 0x000806a1, pf_mask 0x10, 2020-06-26, rev 0x0028, size 32768
sig 0x000806c1, pf_mask 0x80, 2020-10-02, rev 0x0068, size 107520
sig 0x000a0652, pf_mask 0x20, 2020-07-08, rev 0x00e0, size 93184
sig 0x000a0653, pf_mask 0x22, 2020-07-08, rev 0x00e0, size 94208
sig 0x000a0655, pf_mask 0x22, 2020-07-08, rev 0x00e0, size 93184
sig 0x000a0661, pf_mask 0x80, 2020-07-02, rev 0x00e0, size 93184
* Updated Microcodes
sig 0x000306f2, pf_mask 0x6f, 2020-05-27, rev 0x0044, size 34816
sig 0x000406e3, pf_mask 0xc0, 2020-07-14, rev 0x00e2, size 105472
sig 0x00050653, pf_mask 0x97, 2020-06-18, rev 0x1000159, size 33792
sig 0x00050654, pf_mask 0xb7, 2020-06-16, rev 0x2006a08, size 35840
sig 0x00050656, pf_mask 0xbf, 2020-06-18, rev 0x4003003, size 52224
sig 0x00050657, pf_mask 0xbf, 2020-06-18, rev 0x5003003, size 52224
sig 0x000506c9, pf_mask 0x03, 2020-02-27, rev 0x0040, size 17408
sig 0x000506ca, pf_mask 0x03, 2020-02-27, rev 0x001e, size 15360
sig 0x000506e3, pf_mask 0x36, 2020-07-14, rev 0x00e2, size 105472
sig 0x000706a8, pf_mask 0x01, 2020-06-09, rev 0x0018, size 75776
sig 0x000706e5, pf_mask 0x80, 2020-07-30, rev 0x00a0, size 109568
sig 0x000806e9, pf_mask 0x10, 2020-05-27, rev 0x00de, size 104448
sig 0x000806e9, pf_mask 0xc0, 2020-05-27, rev 0x00de, size 104448
sig 0x000806ea, pf_mask 0xc0, 2020-06-17, rev 0x00e0, size 104448
sig 0x000806eb, pf_mask 0xd0, 2020-06-03, rev 0x00de, size 104448
sig 0x000806ec, pf_mask 0x94, 2020-05-18, rev 0x00de, size 104448
sig 0x000906e9, pf_mask 0x2a, 2020-05-26, rev 0x00de, size 104448
sig 0x000906ea, pf_mask 0x22, 2020-05-25, rev 0x00de, size 103424
sig 0x000906eb, pf_mask 0x02, 2020-05-25, rev 0x00de, size 104448
sig 0x000906ec, pf_mask 0x22, 2020-06-03, rev 0x00de, size 103424
sig 0x000906ed, pf_mask 0x22, 2020-05-24, rev 0x00de, size 103424
sig 0x000a0660, pf_mask 0x80, 2020-07-08, rev 0x00e0, size 94208
* 0x806c1: remove the new Tiger Lake update: causes hang on cold/warm boot
https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/44
INTEL-SA-00381 AND INTEL-SA-00389 MITIGATIONS ARE THEREFORE NOT INSTALLED
FOR 0x806c1 TIGER LAKE PROCESSORS by this package update. Contact your
system vendor for a firmware update, or wait fo a possible fix in a future
Intel microcode release.
* source: update symlinks to reflect id of the latest release, 20201110
* source: ship new upstream documentation (security.md, releasenote.md)
Checksums-Sha1:
afeab87974d5a342fe7f87395f2be9ce7f537c81 1821 intel-microcode_3.20201118.1~deb10u1.dsc
ccf6590d7e3863a5d20fcc193a49e53cea6d7a0d 3562524 intel-microcode_3.20201118.1~deb10u1.tar.xz
4c2be64156f76dbf2077b17dbbfbfbb9665374f1 5667 intel-microcode_3.20201118.1~deb10u1_amd64.buildinfo
4fc83e39cfc75a6f2f72fde9d9060a9726440c8e 2767932 intel-microcode_3.20201118.1~deb10u1_amd64.deb
816eb2e3798a744ab709fe5893388f1cc014d0f9 5327 intel-microcode_3.20201118.1~deb10u1_i386.buildinfo
23089859d990e0b107209f557aae2435be1a2d9d 2907208 intel-microcode_3.20201118.1~deb10u1_i386.deb
Checksums-Sha256:
deeed841b0f220ff2651a19b18c301ed2fd6e89c2aa1f141a2a767974b36e2a7 1821 intel-microcode_3.20201118.1~deb10u1.dsc
46e698115aef1cdcf6372018ecd5ff4f63dd5f12883c89e9ac9832bfb8ec09cb 3562524 intel-microcode_3.20201118.1~deb10u1.tar.xz
e8fc5a24b559e601a2d363e65c0dc383ec6b67317580a14849059ad3ed58e417 5667 intel-microcode_3.20201118.1~deb10u1_amd64.buildinfo
7850d17d105cf0e789059f96dd2f8edfcc2a07e2efc6ece472e1dc28f77bfe25 2767932 intel-microcode_3.20201118.1~deb10u1_amd64.deb
3d041df4feea9d2bf0be1f4b38dfafb229d1ff806d737f045287f9a88ceb0fb5 5327 intel-microcode_3.20201118.1~deb10u1_i386.buildinfo
c0a99fbc4a5ac2e94aed82ab290b26fa56818b69c099a9d796e99f1c6ad68b1b 2907208 intel-microcode_3.20201118.1~deb10u1_i386.deb
Files:
5ada7258f032f55f1223af1df4f15f33 1821 non-free/admin standard intel-microcode_3.20201118.1~deb10u1.dsc
7140dd7cc603031471d711af382c47c3 3562524 non-free/admin standard intel-microcode_3.20201118.1~deb10u1.tar.xz
02ecf3e664088700711550534a706b8b 5667 non-free/admin standard intel-microcode_3.20201118.1~deb10u1_amd64.buildinfo
63df220935f1137307b4e8ffeee0cb48 2767932 non-free/admin standard intel-microcode_3.20201118.1~deb10u1_amd64.deb
2ab15e897fb22c5c5e17fe31ee22b851 5327 non-free/admin standard intel-microcode_3.20201118.1~deb10u1_i386.buildinfo
f042ee4436da0ece0fa292fe9af1f7d5 2907208 non-free/admin standard intel-microcode_3.20201118.1~deb10u1_i386.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEQWtPby40keG61F/9KC7xu6bDcIUFAmAUYLsACgkQKC7xu6bD
cIU+LQ/8DVA/ClXfYR4eMCn6+JJo3qQZ3jJDIx2T3AYtWsl1nEfn3R3ZXX06MbBE
ePRiEsd5VFsyNuenv2ekDxnVma1u4SfzC4t1vaxNY/dS3uGGjbkLGYgsaWoVLP3D
yLfd1LTV5KSR4b4a/JMpZP8ff9kh8c9LHmGx+D4b4EykbPGQ+twBoo/U9WfIhH42
FXSBHInBu/trqSF6F3Tes+xMTQcB1U6GQswCg3MsGR0YjG85CKijq3DPxYQ43Nlj
ep4yd0pRGzYM0dNNUCnxQI4ps+qYaRISwgl1BKP8DT5opO70LRlUDY7gTtCih9sP
ycgd0Pmx5fJUiRUUKnACSIUhi8FaqCeVVK3KLUdkuu6UgsvVWGuc42hvJOeIq08F
QD4DTC5jUT/zoe7EO2cy/MiDbY/hAQ01qFYhydEY1q1LAN3z5FOnnqay08BaQ5yT
YVt0/qXgswAdyOM7z2iyDMMu2pGAtkgTj80mqnfff8rDqqRHIn8ulZWp8BDmPnT1
3iSiyb23bVFuazYwF7XD9esiV8jJtoAn7gHW+VU51T9SbItjF7QRy0W/ZEzoQ4eX
4j0HfgD0dxKFbSPlRNubFx/jMRABqCDV83VfruvvAKfqZhzcbRQ2N+5SMOR0cGP5
coefwuBh3EMcQ0UiCpZ7p0kSQr9MxQHCza4FGGKJ6ByLn2OoG6w=
=Y6U7
-----END PGP SIGNATURE-----