Security update for kernel-firmware

Announcement ID: SUSE-SU-2019:1792-1
Rating: moderate
References:
Cross-References:
CVSS scores:
  • CVE-2019-9836 ( SUSE ): 4.7 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
  • CVE-2019-9836 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • CVE-2019-9836 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products:
  • Basesystem Module 15-SP1
  • SUSE Linux Enterprise Desktop 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise Real Time 15 SP1
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP1 Business Critical Linux 15-SP1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • SUSE Manager Proxy 4.0
  • SUSE Manager Retail Branch Server 4.0
  • SUSE Manager Server 4.0

An update that solves one vulnerability and has two security fixes can now be installed.

Description:

This update for kernel-firmware fixes the following issues:

kernel-firmware was updated to version 20190618:

  • cavium: Add firmware for CNN55XX crypto driver.
  • linux-firmware: Update firmware file for Intel Bluetooth 22161
  • linux-firmware: Update firmware file for Intel Bluetooth 9560
  • linux-firmware: Update firmware file for Intel Bluetooth 9260
  • linux-firmware: Update AMD SEV firmware (CVE-2019-9836, bsc#1139383)
  • linux-firmware: update licence text for Marvell firmware
  • linux-firmware: update firmware for mhdp8546
  • linux-firmware: rsi: update firmware images for Redpine 9113 chipset
  • imx: sdma: update firmware to v3.5/v4.5
  • nvidia: update GP10[2467] SEC2 RTOS with the one already used on GP108
  • linux-firmware: Update firmware file for Intel Bluetooth 8265
  • linux-firmware: Update firmware file for Intel Bluetooth 9260
  • linux-firmware: Update firmware file for Intel Bluetooth 9560
  • amlogic: add video decoder firmwares
  • iwlwifi: update -46 firmwares for 22260 and 9000 series
  • iwlwifi: add firmware for 22260 and update 9000 series -46 firmwares
  • iwlwifi: add -46.ucode firmwares for 9000 series
  • amdgpu: update vega20 to the latest 19.10 firmware
  • amdgpu: update vega12 to the latest 19.10 firmware
  • amdgpu: update vega10 to the latest 19.10 firmware
  • amdgpu: update polaris11 to the latest 19.10 firmware
  • amdgpu: update polaris10 to the latest 19.10 firmware
  • amdgpu: update raven2 to the latest 19.10 firmware
  • amdgpu: update raven to the latest 19.10 firmware
  • amdgpu: update picasso to the latest 19.10 firmware
  • linux-firmware: update fw for qat devices
  • Mellanox: Add new mlxsw_spectrum firmware 13.2000.1122
  • drm/i915/firmware: Add ICL HuC v8.4.3238
  • drm/i915/firmware: Add ICL GuC v32.0.3
  • drm/i915/firmware: Add GLK HuC v03.01.2893
  • drm/i915/firmware: Add GLK GuC v32.0.3
  • drm/i915/firmware: Add KBL GuC v32.0.3
  • drm/i915/firmware: Add SKL GuC v32.0.3
  • drm/i915/firmware: Add BXT GuC v32.0.3
  • linux-firmware: Add firmware file for Intel Bluetooth 22161
  • cxgb4: update firmware to revision 1.23.4.0 (bsc#1136334)
  • linux-firmware: Update NXP Management Complex firmware to version 10.14.3
  • linux-firmware: add firmware for MT7615E
  • mediatek: update MT8173 VPU firmware to v1.1.2 [decoder] Enlarge struct vdec_pic_info to support more capture buffer plane and capture buffer format change.
  • linux-firmware: update Marvell 8797/8997 firmware images
  • nfp: update Agilio SmartNIC flower firmware to rev AOTC-2.10.A.23

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • Basesystem Module 15-SP1
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-1792=1

Package List:

  • Basesystem Module 15-SP1 (noarch)
    • ucode-amd-20190618-3.3.1
    • kernel-firmware-20190618-3.3.1

References: