RHSA-2020:5369: Moderate: microcode_ctl security, bug fix and enhancement update

Published Dec 8, 2020
·
Updated

The microcodectl packages provide microcode updates for Intel.Security Fix(es): hw: Information disclosure issue in Intel SGX via RAPL interface (CVE-2020-8695) hw: Vector Register Leakage-Active (CVE-2020-8696) hw: Fast forward store predictor (CVE-2020-8698) Bug Fix(es) and Enhancement(s): Update Intel CPU microcode to microcode-20201027 release, addresses: Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e; Addition of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68; Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0; Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0; Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0; Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision 0xe0; Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode (in intel-06-4e-03/intel-ucode/06-4e-03) from revision 0xdc up to 0xe2; Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006906 up to 0x2006a08; Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode (in intel-06-5e-03/intel-ucode/06-5e-03) from revision 0xdc up to 0xe2; Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xd6 up to 0xde; Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-09) from revision 0xd6 up to 0xde; Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0a) from revision 0xd6 up to 0xe0; Update of 06-8e-0b/0xd0 (WHL-U W0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0b) from revision 0xd6 up to 0xde; Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-8e-0c) from revision 0xd6 up to 0xde; Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-9e-09) from revision 0xd6 up to 0xde; Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0a) from revision 0xd6 up to 0xde; Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0b) from revision 0xd6 up to 0xde; Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0c) from revision 0xd6 up to 0xde; Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode (in intel-06-8e-9e-0x-dell/intel-ucode/06-9e-0d) from revision 0xd6 up to 0xde; Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode from revision 0x43 up to 0x44; Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157 up to 0x1000159; Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01 up to 0x4003003; Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5002f01 up to 0x5003003; Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up to 0x40; Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x16 up to 0x1e; Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up to 0x18; Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78 up to 0xa0; Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca up to 0xe0. Add README file to the documentation directory. Add publicly-sourced codenames list to supply to genprovides.sh; update the latter to handle the somewhat different format. Add SUMMARY.intel-ucode file containing metadata information from the microcode file headers.

Affected Software

1 affected component
Intel microcode_ctl

Remediation

Event History

Dec 8, 2020
Advisory Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2020:5369?

The severity of RHSA-2020:5369 is categorized as critical due to the presence of multiple vulnerabilities.

2

How do I fix RHSA-2020:5369?

To fix RHSA-2020:5369, update your system to the latest version of the microcode_ctl package provided by your distribution.

3

What vulnerabilities are addressed in RHSA-2020:5369?

RHSA-2020:5369 addresses vulnerabilities related to information disclosure in Intel SGX and vector register leakage.

4

Is RHSA-2020:5369 applicable to all Intel processors?

RHSA-2020:5369 specifically affects Intel processors that utilize microcode updates, not all Intel processors may be impacted.

5

What software is affected by RHSA-2020:5369?

RHSA-2020:5369 affects systems running Linux that use the microcode_ctl package for Intel microcode updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203