{"affected":[{"ecosystem_specific":{"binaries":[{"ucode-intel":"20200602-lp151.2.24.1"}]},"package":{"ecosystem":"openSUSE:Leap 15.1","name":"ucode-intel","purl":"pkg:rpm/opensuse/ucode-intel&distro=openSUSE%20Leap%2015.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"20200602-lp151.2.24.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for ucode-intel fixes the following issues:\n\nUpdated Intel CPU Microcode to 20200602 (prerelease) (bsc#1172466)\n  \nThis update contains security mitigations for:\n\n- CVE-2020-0543: Fixed a side channel attack against special registers\n  which could have resulted in leaking of read values to cores other\n  than the one which called it.  This attack is known as Special Register\n  Buffer Data Sampling (SRBDS) or 'CrossTalk' (bsc#1154824).\n- CVE-2020-0548,CVE-2020-0549: Additional ucode updates were supplied to\n  mitigate the Vector Register and L1D Eviction Sampling aka 'CacheOutAttack'\n  attacks. (bsc#1156353)\n\nMicrocode Table:\n\n  Processor             Identifier     Version       Products\n  Model        Stepping F-MO-S/PI      Old->New\n  ---- new platforms ----------------------------------------\n  ---- updated platforms ------------------------------------\n  HSW          C0       6-3c-3/32 00000027->00000028 Core Gen4\n  BDW-U/Y      E0/F0    6-3d-4/c0 0000002e->0000002f Core Gen5\n  HSW-U        C0/D0    6-45-1/72 00000025->00000026 Core Gen4\n  HSW-H        C0       6-46-1/32 0000001b->0000001c Core Gen4\n  BDW-H/E3     E0/G0    6-47-1/22 00000021->00000022 Core Gen5\n  SKL-U/Y      D0       6-4e-3/c0 000000d6->000000dc Core Gen6 Mobile\n  SKL-U23e     K1       6-4e-3/c0 000000d6->000000dc Core Gen6 Mobile\n  SKX-SP       B1       6-55-3/97 01000151->01000157 Xeon Scalable\n  SKX-SP       H0/M0/U0 6-55-4/b7 02000065->02006906 Xeon Scalable\n  SKX-D        M1       6-55-4/b7 02000065->02006906 Xeon D-21xx\n  CLX-SP       B0       6-55-6/bf 0400002c->04002f01 Xeon Scalable Gen2\n  CLX-SP       B1       6-55-7/bf 0500002c->04002f01 Xeon Scalable Gen2\n  SKL-H/S      R0/N0    6-5e-3/36 000000d6->000000dc Core Gen6; Xeon E3 v5\n  AML-Y22      H0       6-8e-9/10 000000ca->000000d6 Core Gen8 Mobile\n  KBL-U/Y      H0       6-8e-9/c0 000000ca->000000d6 Core Gen7 Mobile\n  CFL-U43e     D0       6-8e-a/c0 000000ca->000000d6 Core Gen8 Mobile\n  WHL-U        W0       6-8e-b/d0 000000ca->000000d6 Core Gen8 Mobile\n  AML-Y42      V0       6-8e-c/94 000000ca->000000d6 Core Gen10 Mobile\n  CML-Y42      V0       6-8e-c/94 000000ca->000000d6 Core Gen10 Mobile\n  WHL-U        V0       6-8e-c/94 000000ca->000000d6 Core Gen8 Mobile\n  KBL-G/H/S/E3 B0       6-9e-9/2a 000000ca->000000d6 Core Gen7; Xeon E3 v6\n  CFL-H/S/E3   U0       6-9e-a/22 000000ca->000000d6 Core Gen8 Desktop, Mobile, Xeon E\n  CFL-S        B0       6-9e-b/02 000000ca->000000d6 Core Gen8\n  CFL-H/S      P0       6-9e-c/22 000000ca->000000d6 Core Gen9\n  CFL-H        R0       6-9e-d/22 000000ca->000000d6 Core Gen9 Mobile\n\nAlso contains the Intel CPU Microcode update to 20200520:\n\n  Processor             Identifier     Version       Products\n  Model        Stepping F-MO-S/PI      Old->New\n  ---- new platforms ----------------------------------------\n  ---- updated platforms ------------------------------------\n  SNB-E/EN/EP  C1/M0    6-2d-6/6d 0000061f->00000621 Xeon E3/E5, Core X\n  SNB-E/EN/EP  C2/M1    6-2d-7/6d 00000718->0000071a Xeon E3/E5, Core X\n\nThis update was imported from the SUSE:SLE-15-SP1:Update update project.","id":"openSUSE-SU-2020:0791-1","modified":"2020-06-10T17:58:41Z","published":"2020-06-10T17:58:41Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/FEGYVZIAZERXLY4SF7SWJUPJOF7CD7LU/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154824"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156353"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-0543"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-0548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-0549"}],"related":["CVE-2020-0543","CVE-2020-0548","CVE-2020-0549"],"summary":"Security update for ucode-intel","upstream":["CVE-2020-0543","CVE-2020-0548","CVE-2020-0549"]}