{"id":45892,"date":"2023-07-31T21:28:41","date_gmt":"2023-07-31T17:28:41","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/173838\/dsa-5462-1.txt"},"modified":"2023-08-02T13:38:08","modified_gmt":"2023-08-02T09:08:08","slug":"debian-security-advisory-5462-1","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/debian-security-advisory-5462-1\/","title":{"rendered":"Debian Security Advisory 5462-1"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA512<\/p>\n<p>&#8211; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nDebian Security Advisory DSA-5462-1 security@debian.org<br \/>\nhttps:\/\/www.debian.org\/security\/ Salvatore Bonaccorso<br \/>\nJuly 30, 2023 https:\/\/www.debian.org\/security\/faq<br \/>\n&#8211; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>Package : linux<br \/>\nCVE ID : CVE-2023-20593<\/p>\n<p>Tavis Ormandy discovered that under specific microarchitectural<br \/>\ncircumstances, a vector register in AMD &#8220;Zen 2&#8221; CPUs may not be<br \/>\nwritten to 0 correctly. This flaw allows an attacker to leak<br \/>\nsensitive information across concurrent processes, hyper threads<br \/>\nand virtualized guests.<\/p>\n<p>For details please refer to<br \/>\n&lt;https:\/\/lock.cmpxchg8b.com\/zenbleed.html&gt; and<br \/>\n&lt;https:\/\/github.com\/google\/security-research\/security\/advisories\/GHSA-v6wh-rxpg-cmm8&gt;.<\/p>\n<p>This issue can also be mitigated by a microcode update through the<br \/>\namd64-microcode package or a system firmware (BIOS\/UEFI) update.<br \/>\nHowever, the initial microcode release by AMD only provides<br \/>\nupdates for second generation EPYC CPUs. Various Ryzen CPUs are<br \/>\nalso affected, but no updates are available yet.<\/p>\n<p>For the stable distribution (bookworm), this problem has been fixed in<br \/>\nversion 6.1.38-2.<\/p>\n<p>We recommend that you upgrade your linux packages.<\/p>\n<p>For the detailed security status of linux please refer to its security<br \/>\ntracker page at:<br \/>\nhttps:\/\/security-tracker.debian.org\/tracker\/linux<\/p>\n<p>Further information about Debian Security Advisories, how to apply<br \/>\nthese updates to your system and frequently asked questions can be<br \/>\nfound at: https:\/\/www.debian.org\/security\/<\/p>\n<p>Mailing list: debian-security-announce@lists.debian.org<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmTGCyRfFIAAAAAALgAo<br \/>\naXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2<br \/>\nNDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND<br \/>\nz0Tjjw\/\/SsbN4RnQHqV1G0XVWxApVK1DYoKw6+tHxkkf301jV2abDMcIO1keVNol<br \/>\ngc2yENQyzeoGd++eBqO0MD9GnvrbutT6n7wChuyvB7bzFDQQA6hJHLcFLkKYA3D1<br \/>\n6yFgczWL0Tx7wcrpKU9gVMWAe928VE4hJGVd6nFF02YS0GF8voY\/ymiCqbuQA05f<br \/>\nLOmeHNIWyzulBG0qNwQE6HT6s6LkLMCZAawpe3D85cE6exFWRDKJhxKY8GcZvJDV<br \/>\n8G80Ik1xYAQ6Q5HqwxUr2Rp0sN7a8SghF817Sn\/Bx6ahvej61ZTgDn7QhKLkGwu2<br \/>\n\/DOnMcKwKd9WB7gS9T4YLd6rNOPCL4J5P06ia4\/JbocExIu19pEEfQvb7gf5PVl3<br \/>\n994DykFy9ByKiXYh91U9QNyKaBZSjMFeN9Mg8FbbuwZGLLNACkhZc72JK4yKsxTq<br \/>\n5cucuVBzwbwvvrK63h3YVDyOv8vRiI\/jquxOMehsrSGOuaHpd2VduQdnS0ayKjqX<br \/>\nSTOKNRMA+GGjIoNdLyfe9HDlm3ztwsjrxoO0eXqWjUc7EA6KOfsF7NLFju2YXEt9<br \/>\n80Yr6kCS5\/IukkhZBAP4GwV4mLKG1yZ7vzwb15pAihvtw7UFrrzifkcL0yPf7Cx8<br \/>\nwVtTUdl+5Y4Dfy+i9\/LT0sY4fVEKfZZoXnDV733vxTTKKNQSpFk=<br \/>\n=ceVi<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA512 &#8211; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- Debian Security Advisory DSA-5462-1 security@debian.org https:\/\/www.debian.org\/security\/ Salvatore Bonaccorso July 30, 2023 https:\/\/www.debian.org\/security\/faq &#8211; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- Package : linux CVE ID : CVE-2023-20593 Tavis Ormandy discovered that under specific microarchitectural circumstances, a vector register in AMD &#8220;Zen 2&#8221; CPUs may not be written to 0 correctly. This flaw allows &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45892","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=45892"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45892\/revisions"}],"predecessor-version":[{"id":45995,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45892\/revisions\/45995"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=45892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=45892"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=45892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}