Discussion:
Bug#1089279: bookworm-pu: package intel-microcode/3.20241112.1~deb12u1
(too old to reply)
Henrique de Moraes Holschuh
2024-12-07 18:40:02 UTC
Permalink
Package: release.debian.org
Severity: normal
Tags: bookworm
User: ***@packages.debian.org
Usertags: pu

[ Reason ]

As requested by the security team, I would like to bring the microcode
update level for Intel processors in Bookworm to match what we have in Sid
and Trixie.

This fixes:
- Mitigations for INTEL-SA-01101 (CVE-2024-21853)
- Mitigations for INTEL-SA-01079 (CVE-2024-23918)
- Updated mitigations for INTEL-SA-01097 (CVE-2024-24968)
- Mitigations for INTEL-SA-01103 (CVE-2024-23984)
* Other unspecified functional issues on several processors

There are no releavant issues reported on this microcode update,
considering the version of intel-microcode already available as security
updates for Bookworm.

[ Impact ]

If this update is not approved, owners of most recent "client" Intel
processors and a few server processors will depend on UEFI updates to be
protected from the issues listed above.

[ Tests ]

There were no bug reports from users of Debian sid or Trixie, these
packages have been tested there since 2024-11-14 (sid), 2024-11-20
(trixie).

[ Risks ]

Unknown, but not believed to be any different from other Intel microcode
updates.

[ Checklist ]

[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable

[ Changes ]

As per the debdiff, only documentation changes, package documentation
changes, and the binary blob change from upstream.

changelog | 66 ++++++++++++++++++++++++++++++++++++---
debian/changelog | 86 +++++++++++++++++++++++++++++++++++++++++++++++----
intel-ucode/06-8f-05 |binary
intel-ucode/06-8f-06 |binary
intel-ucode/06-8f-07 |binary
intel-ucode/06-8f-08 |binary
intel-ucode/06-97-02 |binary
intel-ucode/06-97-05 |binary
intel-ucode/06-9a-03 |binary
intel-ucode/06-9a-04 |binary
intel-ucode/06-aa-04 |binary
intel-ucode/06-b7-01 |binary
intel-ucode/06-ba-02 |binary
intel-ucode/06-ba-03 |binary
intel-ucode/06-ba-08 |binary
intel-ucode/06-bf-02 |binary
intel-ucode/06-bf-05 |binary
intel-ucode/06-cf-01 |binary
intel-ucode/06-cf-02 |binary
releasenote.md | 72 ++++++++++++++++++++++++++++++++++++++++++
20 files changed, 213 insertions(+), 11 deletions(-)

[ Other info ]

The package version with "~" is needed to guarantee smooth updates to
the next debian release.
--
Henrique Holschuh
Jonathan Wiltshire
2024-12-09 12:10:01 UTC
Permalink
Control: tag -1 confirmed

Please go ahead.

Thanks,
--
Jonathan Wiltshire ***@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1
Henrique de Moraes Holschuh
2024-12-10 11:40:02 UTC
Permalink
Post by Jonathan Wiltshire
Control: tag -1 confirmed
Uploaded. Thank you!
--
Henrique de Moraes Holschuh <***@debian.org>
Debian Bug Tracking System
2024-12-09 12:10:01 UTC
Permalink
Post by Jonathan Wiltshire
tag -1 confirmed
Bug #1089279 [release.debian.org] bookworm-pu: package intel-microcode/3.20241112.1~deb12u1
Added tag(s) confirmed.
--
1089279: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1089279
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Jonathan Wiltshire
2024-12-18 13:30:02 UTC
Permalink
package release.debian.org
tags 1089279 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==============

Package: intel-microcode
Version: 3.20241112.1~deb12u1

Explanation: new upstream security release [CVE-2024-21853 CVE-2024-23918 CVE-2024-24968 CVE-2024-23984]
Debian Bug Tracking System
2024-12-18 13:30:02 UTC
Permalink
Post by Jonathan Wiltshire
package release.debian.org
Limiting to bugs with field 'package' containing at least one of 'release.debian.org'
Limit currently set to 'package':'release.debian.org'
Post by Jonathan Wiltshire
tags 1089279 = bookworm pending
Bug #1089279 [release.debian.org] bookworm-pu: package intel-microcode/3.20241112.1~deb12u1
Added tag(s) pending; removed tag(s) confirmed.
Post by Jonathan Wiltshire
thanks
Stopping processing here.

Please contact me if you need assistance.
--
1089279: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1089279
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Debian Bug Tracking System
2025-01-11 11:20:01 UTC
Permalink
Your message dated Sat, 11 Jan 2025 11:03:09 +0000
with message-id <E1tWZGn-009jYo-***@coccia.debian.org>
and subject line Close 1089279
has caused the Debian Bug report #1089279,
regarding bookworm-pu: package intel-microcode/3.20241112.1~deb12u1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
1089279: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1089279
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Loading...