USN-3531-2: Intel Microcode regression
USN-3531-1 updated Intel microcode to the 20180108 release. Regressions were discovered in the microcode updates which could cause system instability on certain hardware platforms. At the request of Intel, we have reverted to the previous packaged microcode version, the 20170707 release. Original advisory details: It was discovered that microprocessors utilizing speculative execution and branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Spectre. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2017-5715) This update provides the microcode updates required for the corresponding Linux kernel updates.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is USN-3531-2.
What is the title of the vulnerability?
The title of the vulnerability is "Intel Microcode regression".
What is the description of the vulnerability?
The description of the vulnerability is that regressions were discovered in the microcode updates which could cause system instability on certain hardware platforms.
What software is affected by this vulnerability?
The affected software is Ubuntu Intel Microcode version 3.20180108.0+really20170707ubuntu17.10.1, 3.20180108.0+really20170707ubuntu16.04.1, and 3.20180108.0+really20170707ubuntu14.04.1.
How can I fix the vulnerability?
To fix the vulnerability, revert to the previous packaged microcode version, the 20170707 release.