diff --git a/.gitignore b/.gitignore index b0f5536..86c5d23 100644 --- a/.gitignore +++ b/.gitignore @@ -16,3 +16,5 @@ SOURCES/ibt-20-1-3.sfi SOURCES/ibt-20-1-4.sfi SOURCES/ibt-hw-37.8.10-fw-22.50.19.14.f.bseq SOURCES/linux-firmware-20200421.tar.gz +SOURCES/microcode_amd_fam17h.bin +SOURCES/microcode_amd_fam19h.bin diff --git a/.linux-firmware.metadata b/.linux-firmware.metadata index 644ed05..ca98524 100644 --- a/.linux-firmware.metadata +++ b/.linux-firmware.metadata @@ -16,3 +16,5 @@ 858beec242af187021b58b664fe694dfe2fae86e SOURCES/ibt-20-1-4.sfi 851029db5a5467466ad0c1ddfeb21028747c27f6 SOURCES/ibt-hw-37.8.10-fw-22.50.19.14.f.bseq 0fe79d9a46eb538e59c36036ba81355473ca60a2 SOURCES/linux-firmware-20200421.tar.gz +219ff6cb94628467afb895dcce586e462ad7a879 SOURCES/microcode_amd_fam17h.bin +045a761b6f06f9a99942ebd49a3a043a08365345 SOURCES/microcode_amd_fam19h.bin diff --git a/SOURCES/microcode_amd_fam17h.bin.asc b/SOURCES/microcode_amd_fam17h.bin.asc new file mode 100644 index 0000000..34a4024 --- /dev/null +++ b/SOURCES/microcode_amd_fam17h.bin.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCgAdFiEE/HxsUF2vzBRxg1fK5L5TOfMornMFAmS4Mm4ACgkQ5L5TOfMo +rnN35wgAkllCunxE6J5hQyLMx5o4WTHZkbNvXmu6nV1Y3vjiL1oeaK+pmx8BlkPt +fGZJCe/068kqmp3N4EtOZLxXn55t3jNBYectPr0RmFqpjMsEJEcfXfuXROA4N9Ti +Zd/o6X21eHEsm0kK0q4YfppfgTd5Ze7k1jTkUuuU6/yh6uRk1MiFreEzkPO3Aayh +iEWlYx33vq3HccTPgdY3D64Zr8gmgKG+8mdEvqb1jK4SVZ1/9vy4OKIIpUZB/eqx +46h9Ejwn9pktnYkHi/A/zCREEcIQ10HXFF5bjxJTFQkM5S46/QEO7uuvnpMb+6Yy +4V1/QIWMG6ixqCRx9GqbBK7GHdYODw== +=+IsI +-----END PGP SIGNATURE----- diff --git a/SOURCES/microcode_amd_fam19h.bin.asc b/SOURCES/microcode_amd_fam19h.bin.asc new file mode 100644 index 0000000..3955e52 --- /dev/null +++ b/SOURCES/microcode_amd_fam19h.bin.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCgAdFiEE/HxsUF2vzBRxg1fK5L5TOfMornMFAmUoW6AACgkQ5L5TOfMo +rnMHAAf/SxaKEu5l7FGXR+QJYc2oSJDpf9ZsHTkVnxqF1I3ReItEGAR3iqSWrsRw +KA4niP9Ihr8EqwhOaOtqkRKKF9D5yg+DksnRWbh2VTUECO4KQxjHNrPp3JWEzBwb +Xn+vRVP02ZRi3u4MCYbnDC4AfUSnKnldY3TTlNi/6HUaGS2pcw8Vjli/C06zwfgh +WwUAoFMQl4SDJhbGfC9cb93MKjBl/0Hv4uhK5W8fJ1iUkMvY8Ijna/oDTZCNPqP0 +0AgOwdAdzoyOYWjbUXcwofz2Umpz12xmJW8yXNwdv1pmaCvv9aCJz1L49lGwFH9E +lhhoFQ1SQL3hhPjTXO6DbeeT9+fjOg== +=9Xav +-----END PGP SIGNATURE----- diff --git a/SPECS/linux-firmware.spec b/SPECS/linux-firmware.spec index 6237b15..753d670 100644 --- a/SPECS/linux-firmware.spec +++ b/SPECS/linux-firmware.spec @@ -1,5 +1,5 @@ %global checkout 78c0348 -%global firmware_release 80 +%global firmware_release 81 %define _binary_payload w9.xzdio @@ -51,6 +51,11 @@ Source30: ibt-20-1-3.sfi Source31: ibt-20-1-4.ddc Source32: ibt-20-1-4.sfi Source33: ibt-hw-37.8.10-fw-22.50.19.14.f.bseq +# RHEL-9250 and RHEL-8938 (CVE-2023-20569 and CVE-2023-20593) +Source34: microcode_amd_fam17h.bin +Source35: microcode_amd_fam17h.bin.asc +Source36: microcode_amd_fam19h.bin +Source37: microcode_amd_fam19h.bin.asc BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) BuildArch: noarch @@ -297,6 +302,11 @@ cp %{_sourcedir}/ibt-20-1-3.sfi intel/ cp %{_sourcedir}/ibt-20-1-4.ddc intel/ cp %{_sourcedir}/ibt-20-1-4.sfi intel/ cp %{_sourcedir}/ibt-hw-37.8.10-fw-22.50.19.14.f.bseq intel/ +# RHEL-9250 and RHEL-8938 (CVE-2023-20569 and CVE-2023-20593) +cp %{_sourcedir}/microcode_amd_fam17h.bin amd-ucode/ +cp %{_sourcedir}/microcode_amd_fam17h.bin.asc amd-ucode/ +cp %{_sourcedir}/microcode_amd_fam19h.bin amd-ucode/ +cp %{_sourcedir}/microcode_amd_fam19h.bin.asc amd-ucode/ %build @@ -462,6 +472,10 @@ rm -rf $RPM_BUILD_ROOT %doc WHENCE LICENCE.* LICENSE.* %changelog +* Thu Oct 26 2023 Rado Vrbovsky - 20200421-80.git78c0348 +- Cross-Process Information Leak (RHEL-8938) +- Return Address Predictor velunerability leading to information disclosure (RHEL-9250) + * Sat Dec 12 2020 Augusto Caringi - 20200421-80.git78c0348 - Update Intel Bluetooth firmwares (rhbz 1895787)