RHSA-2021:3028: Important: microcode_ctl security, bug fix and enhancement update
The microcodectl packages provide microcode updates for Intel.<br>Security Fix(es):<br><li> hw: Special Register Buffer Data Sampling (SRBDS) (CVE-2020-0543)</li> <li> hw: Vector Register Data Sampling (CVE-2020-0548)</li> <li> hw: L1D Cache Eviction Sampling (CVE-2020-0549)</li> <li> hw: vt-d related privilege escalation (CVE-2020-24489)</li> <li> hw: improper isolation of shared resources in some Intel Processors</li> (CVE-2020-24511)<br><li> hw: observable timing discrepancy in some Intel Processors</li> (CVE-2020-24512)<br><li> hw: Information disclosure issue in Intel SGX via RAPL interface</li> (CVE-2020-8695)<br><li> hw: Vector Register Leakage-Active (CVE-2020-8696)</li> <li> hw: Fast forward store predictor (CVE-2020-8698)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities are addressed in RHSA-2021:3028?
RHSA-2021:3028 addresses vulnerabilities related to Special Register Buffer Data Sampling (CVE-2020-0543), Vector Register Data Sampling (CVE-2020-0548), and L1D Cache Eviction Sampling (CVE-2020-0549).
What is the severity of RHSA-2021:3028?
The severity of RHSA-2021:3028 is categorized as critical due to the potential impact on confidential data exposure and side-channel attacks.
How do I fix RHSA-2021:3028?
To fix RHSA-2021:3028, you should update the microcode_ctl package as provided in the advisory.
Which systems are affected by RHSA-2021:3028?
RHSA-2021:3028 affects systems running on Intel architecture that utilize the microcode_ctl package for updates.
Is there a workaround for RHSA-2021:3028 until I can apply the update?
Currently, there are no known workarounds for RHSA-2021:3028, so applying the update is recommended as soon as possible.