[Git][security-tracker-team/security-tracker][master] Update status for CVE-2023-20592/amd64-microcode

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Nov 15 07:59:45 GMT 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1e2dcf61 by Salvatore Bonaccorso at 2023-11-15T08:56:56+01:00
Update status for CVE-2023-20592/amd64-microcode

Updates fuer 3rd Gen AMD EPYC Processors/Milan with patchlevel
0x0A0011D1 and 0x0A001234 were already included in the 3.20230719.1
uploads.

No mitigation is available for the first or second generations of EPYC
processors.

4th Gen AMD EPYC Processors/Genoa are found to be not impacted by the
issue.

Thus consider as fixed version the one which includes the microcode
updates for Milan.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -70063,7 +70063,10 @@ CVE-2023-20593 (An issue in \u201cZen 2\u201d CPUs, under specific microarchitec
 	NOTE: 3.20230719.1 ships the first batch of fixes, only for 2nd gen Epyc CPUs, further
 	NOTE: CPUs to follow in later releases
 CVE-2023-20592 (Improper or unexpected behavior of the INVD instruction in some AMD CP ...)
-	- amd64-microcode <unfixed>
+	- amd64-microcode 3.20230719.1
+	[bookworm] - amd64-microcode 3.20230719.1~deb12u1
+	[bullseye] - amd64-microcode 3.20230719.1~deb11u1
+	[buster] - amd64-microcode 3.20230719.1~deb10u1
 	NOTE: https://cachewarpattack.com/
 	NOTE: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3005.html
 CVE-2023-20591



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e2dcf6185281feaad035feec73a0bf556cc6ea0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e2dcf6185281feaad035feec73a0bf556cc6ea0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231115/5ad4ac2a/attachment.htm>


More information about the debian-security-tracker-commits mailing list