Back to intel-microcode PTS page

Accepted intel-microcode 3.20220207.1~deb10u1 (amd64 i386 source) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 20 Mar 2022 18:19:10 -0300
Binary: intel-microcode
Source: intel-microcode
Architecture: amd64 i386 source
Version: 3.20220207.1~deb10u1
Distribution: buster
Urgency: medium
Maintainer: Henrique de Moraes Holschuh <hmh@debian.org>
Changed-By: Henrique de Moraes Holschuh <hmh@debian.org>
Description: 
 intel-microcode - Processor microcode firmware for Intel CPUs
Changes:
 intel-microcode (3.20220207.1~deb10u1) buster; urgency=medium
 .
   * Backport for Debian oldstable (no changes)
   * Release manager: this is the same package already in bullseye-backports,
     testing and unstable.  It fixes several security issues, adds MSRs that
     can be enabled by updated kernels for enhanced security mitigaton, and
     also fixes several critical "functional issues" (i.e.  processor errata).
     There were no reports to date of regressions introduced by this microcode
     drelease.
 .
 intel-microcode (3.20220207.1) unstable; urgency=medium
 .
   * upstream changelog: new upstream datafile 20220207
     * Mitigates (*only* when loaded from UEFI firmware through the FIT)
       CVE-2021-0146, INTEL-SA-00528: VT-d privilege escalation through
       debug port, on Pentium, Celeron and Atom processors with signatures
       0x506c9, 0x506ca, 0x506f1, 0x706a1, 0x706a8
       https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/57#issuecomment-1036363145
     * Mitigates CVE-2021-0127, INTEL-SA-00532: an unexpected code breakpoint
       may cause a system hang, on many processors.
     * Mitigates CVE-2021-0145, INTEL-SA-00561: information disclosure due
       to improper sanitization of shared resources (fast-store forward
       predictor), on many processors.
     * Mitigates CVE-2021-33120, INTEL-SA-00589: out-of-bounds read on some
       Atom Processors may allow information disclosure or denial of service
       via network access.
     * Fixes critical errata (functional issues) on many processors
     * Adds a MSR switch to enable RAPL filtering (default off, once enabled
       it can only be disabled by poweroff or reboot).  Useful to protect
       SGX and other threads from side-channel info leak.  Improves the
       mitigation for CVE-2020-8694, CVE-2020-8695, INTEL-SA-00389 on many
       processors.
     * Disables TSX in more processor models.
     * Fixes issue with WBINDV on multi-socket (server) systems which could
       cause resets and unpredictable system behavior.
     * Adds a MSR switch to 10th and 11th-gen (Ice Lake, Tiger Lake, Rocket
       Lake) processors, to control a fix for (hopefully rare) unpredictable
       processor behavior when HyperThreading is enabled.  This MSR switch
       is enabled by default on *server* processors.  On other processors,
       it needs to be explicitly enabled by an updated UEFI/BIOS (with added
       configuration logic).  An updated operating system kernel might also
       be able to enable it.  When enabled, this fix can impact performance.
     * Updated Microcodes:
       sig 0x000306f2, pf_mask 0x6f, 2021-08-11, rev 0x0049, size 38912
       sig 0x000306f4, pf_mask 0x80, 2021-05-24, rev 0x001a, size 23552
       sig 0x000406e3, pf_mask 0xc0, 2021-04-28, rev 0x00ec, size 105472
       sig 0x00050653, pf_mask 0x97, 2021-05-26, rev 0x100015c, size 34816
       sig 0x00050654, pf_mask 0xb7, 2021-06-16, rev 0x2006c0a, size 43008
       sig 0x00050656, pf_mask 0xbf, 2021-08-13, rev 0x400320a, size 35840
       sig 0x00050657, pf_mask 0xbf, 2021-08-13, rev 0x500320a, size 36864
       sig 0x0005065b, pf_mask 0xbf, 2021-06-04, rev 0x7002402, size 28672
       sig 0x00050663, pf_mask 0x10, 2021-06-12, rev 0x700001c, size 28672
       sig 0x00050664, pf_mask 0x10, 2021-06-12, rev 0xf00001a, size 27648
       sig 0x00050665, pf_mask 0x10, 2021-09-18, rev 0xe000014, size 23552
       sig 0x000506c9, pf_mask 0x03, 2021-05-10, rev 0x0046, size 17408
       sig 0x000506ca, pf_mask 0x03, 2021-05-10, rev 0x0024, size 16384
       sig 0x000506e3, pf_mask 0x36, 2021-04-29, rev 0x00ec, size 108544
       sig 0x000506f1, pf_mask 0x01, 2021-05-10, rev 0x0036, size 11264
       sig 0x000606a6, pf_mask 0x87, 2021-12-03, rev 0xd000331, size 291840
       sig 0x000706a1, pf_mask 0x01, 2021-05-10, rev 0x0038, size 74752
       sig 0x000706a8, pf_mask 0x01, 2021-05-10, rev 0x001c, size 75776
       sig 0x000706e5, pf_mask 0x80, 2021-05-26, rev 0x00a8, size 110592
       sig 0x000806a1, pf_mask 0x10, 2021-09-02, rev 0x002d, size 34816
       sig 0x000806c1, pf_mask 0x80, 2021-08-06, rev 0x009a, size 109568
       sig 0x000806c2, pf_mask 0xc2, 2021-07-16, rev 0x0022, size 96256
       sig 0x000806d1, pf_mask 0xc2, 2021-07-16, rev 0x003c, size 101376
       sig 0x000806e9, pf_mask 0x10, 2021-04-28, rev 0x00ec, size 104448
       sig 0x000806e9, pf_mask 0xc0, 2021-04-28, rev 0x00ec, size 104448
       sig 0x000806ea, pf_mask 0xc0, 2021-04-28, rev 0x00ec, size 103424
       sig 0x000806eb, pf_mask 0xd0, 2021-04-28, rev 0x00ec, size 104448
       sig 0x000806ec, pf_mask 0x94, 2021-04-28, rev 0x00ec, size 104448
       sig 0x00090661, pf_mask 0x01, 2021-09-21, rev 0x0015, size 20480
       sig 0x000906c0, pf_mask 0x01, 2021-08-09, rev 0x2400001f, size 20480
       sig 0x000906e9, pf_mask 0x2a, 2021-04-29, rev 0x00ec, size 106496
       sig 0x000906ea, pf_mask 0x22, 2021-04-28, rev 0x00ec, size 102400
       sig 0x000906eb, pf_mask 0x02, 2021-04-28, rev 0x00ec, size 104448
       sig 0x000906ec, pf_mask 0x22, 2021-04-28, rev 0x00ec, size 103424
       sig 0x000906ed, pf_mask 0x22, 2021-04-28, rev 0x00ec, size 103424
       sig 0x000a0652, pf_mask 0x20, 2021-04-28, rev 0x00ec, size 93184
       sig 0x000a0653, pf_mask 0x22, 2021-04-28, rev 0x00ec, size 94208
       sig 0x000a0655, pf_mask 0x22, 2021-04-28, rev 0x00ee, size 94208
       sig 0x000a0660, pf_mask 0x80, 2021-04-28, rev 0x00ea, size 94208
       sig 0x000a0661, pf_mask 0x80, 2021-04-29, rev 0x00ec, size 93184
       sig 0x000a0671, pf_mask 0x02, 2021-08-29, rev 0x0050, size 102400
     * Removed Microcodes:
       sig 0x00080664, pf_mask 0x01, 2021-02-17, rev 0xb00000f, size 130048
       sig 0x00080665, pf_mask 0x01, 2021-02-17, rev 0xb00000f, size 130048
   * update .gitignore and debian/.gitignore.
     Add some missing items from .gitignore and debian/.gitignore.
   * ucode-blacklist: do not late-load 0x406e3 and 0x506e3.
     When the BIOS microcode is older than revision 0x7f (and perhaps in some
     other cases as well), the latest microcode updates for 0x406e3 and
     0x506e3 must be applied using the early update method.  Otherwise, the
     system might hang.  Also: there must not be any other intermediate
     microcode update attempts [other than the one done by the BIOS itself],
     either.  It must go from the BIOS microcode update directly to the
     latest microcode update.
   * source: update symlinks to reflect id of the latest release, 20220207
Checksums-Sha1: 
 d6b65066902fa5d83e684bc90fe776806fbf6921 1821 intel-microcode_3.20220207.1~deb10u1.dsc
 e9aa603acdae208f2fdc8387bc50203ffa15ad19 4520440 intel-microcode_3.20220207.1~deb10u1.tar.xz
 1a38c6544aef965bc5fc6bd3110d8f9d0e5404ee 5708 intel-microcode_3.20220207.1~deb10u1_amd64.buildinfo
 6ddf4e22705e6ecd6bed3bd222be91e017e695e9 3846088 intel-microcode_3.20220207.1~deb10u1_amd64.deb
 c973d49dab3efc31365f9e2ad45772c7e7074824 4485 intel-microcode_3.20220207.1~deb10u1_i386.buildinfo
 bc95d7d6866f1b7741a4bdc85ed4eae729146410 3986000 intel-microcode_3.20220207.1~deb10u1_i386.deb
Checksums-Sha256: 
 8c63b7db6cd7ec501f03a6942066e7957f2bd8ac454fb0c2528b48432c2e7306 1821 intel-microcode_3.20220207.1~deb10u1.dsc
 637af6418a43e5c1b87d3de5ebb1b8d82aa3ba02a0bbed0ecd2abb7acdd70b17 4520440 intel-microcode_3.20220207.1~deb10u1.tar.xz
 5a5d022191088f217601d357d6bd372afbf9e8fa4e8d8502f2c8bc5115dae821 5708 intel-microcode_3.20220207.1~deb10u1_amd64.buildinfo
 eba81524ee4eb5aba641158fa42870d664132e8f8fe4f74b501e72b27d75efae 3846088 intel-microcode_3.20220207.1~deb10u1_amd64.deb
 1b1045180a44182f00f0f41ca435bffe71da6946b14035133ece293dc43a85a1 4485 intel-microcode_3.20220207.1~deb10u1_i386.buildinfo
 815f3a38583124929a4644dc04bb39e15a62ad6a0ef2659a7ab4474d1682c6e6 3986000 intel-microcode_3.20220207.1~deb10u1_i386.deb
Files: 
 a024cfcf7bf55b5f067068a0f9c5de71 1821 non-free/admin standard intel-microcode_3.20220207.1~deb10u1.dsc
 1d40424345b6fa02f2d4cc44a6e5a318 4520440 non-free/admin standard intel-microcode_3.20220207.1~deb10u1.tar.xz
 a945753780c495629915302dd80e3517 5708 non-free/admin standard intel-microcode_3.20220207.1~deb10u1_amd64.buildinfo
 d976b34db958ecfa6b1955ffef0f43e7 3846088 non-free/admin standard intel-microcode_3.20220207.1~deb10u1_amd64.deb
 ec7ce1b510ab820f691d4e49f813d896 4485 non-free/admin standard intel-microcode_3.20220207.1~deb10u1_i386.buildinfo
 2836ec44d312dd7a5fc77f0b457411af 3986000 non-free/admin standard intel-microcode_3.20220207.1~deb10u1_i386.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEIXEYtQeAQUHyKjs9TkVcVzAplOQFAmI3nHkACgkQTkVcVzAp
lOSn4w//aZZowIA/jBgWKNmUmWmYGM3EQXCHwJq7M1eHofTy+bH2hKLFUmhPmDMb
gejLm2zxX6cg0SgELG0UbFYOCGlYPQfx1JXjNCbaysAYeaOY09PULN8ybhKyRhFZ
7zS5iNrYtzGANrgYIvzpvKqOLTyZ9n537yXDZgZHua7zk3/woPahVl25bsfXzlh/
k992igt+DwA3agKQI5snfAqUkCehQCYWduFzOmCGkmgsZPumL0vUY4tGWrROca31
H8eMrj9xANj0mkvQ9HcoglqRAVFoUN7/sG5puLakXmx2+obMcFbERMaZyNRxDU6p
Ml5TTgWzBZK3Gh7lxkgzdnFZfoSLv2q13GjcDsgZ/1U4Fa0WCo7T7N6HTCsS4PYo
XNavEHYbFvhgTFY0jXBILjLn1QpO45zCoTGRsnzJsLtwYy5NYXpOAkVnSxxtE5fq
NXc1fAvOKccJQAmR5Yq3JxKKE+q57c4v+qY5QfEzzk97VClWjjEXXLDqjEcxoadL
iXMNWLOqJ1HAouPsLwMzTq0wNyWDuWWZxg0NmDWoQ9+vp1Z0NnPmx7lzT5cAtIQv
invjkrKJ8cxqJ5hdYUlS2RSExg8hxhDYM/ft4AwXjPJOfpnwe/R0rIyJTPcQoR7d
Ep+mg+wvxbUVK5O/RFcRx/tAk1MAAr2uofOvhfmJn2U9h9dl1bE=
=sOhV
-----END PGP SIGNATURE-----