Plugins Database As of 12-10-2019

RedHat Update for linux-firmware RHSA-2018:0094-01

Red Hat Local Security Checks
Impact by CVSS Score
  • ID: 1.3.6.1.4.1.25623.1.0.910001

CVSS Base Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N

Detection Type:
Linux Distribution Package

Summary:
The remote host is missing an update for the 'linux-firmware' Linux Distribution Package(s) announced via the referenced advisory.

Detection Method:
Checks if a vulnerable version is present on the target host.

Technical Details:
The linux-firmware Linux Distribution Packages contain all of the firmware files that are required by various devices to operate. This update supersedes microcode provided by Red Hat with the CVE-2017-5715 (Spectre) CPU branch injection vulnerability mitigation. (Historically, Red Hat has provided updated microcode, developed by our microprocessor partners, as a customer convenience.) Further testing has uncovered problems with the microcode provided along with the Spectre mitigation that could lead to system instabilities. As a result, Red Hat is providing an microcode update that reverts to the last known good microcode version dated before 03 January 2018. Red Hat strongly recommends that customers contact their hardware provider for the latest microcode updates. IMPORTANT: Customers using Intel Skylake-, Broadwell-, and Haswell-based platforms must obtain and install updated microcode from their hardware vendor immediately. The 'Spectre' mitigation requires both an updated kernel from Red Hat and updated microcode from your hardware vendor.

Affected Versions:
linux-firmware on Red Hat Enterprise Linux Server (v. 7)

Recommendations:
Please Install the Updated Packages.

Solution Type:
Vendor Patch

Search
Severity
Medium
CVSS Score
4.7
Published
2018-01-17 06:35:13
Modified
2018-11-23 08:28:21
CVE
CVE-2017-5715

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.