• Accepted amd64-microcode 3.20240820.1~deb12u1 (source) into proposed-up

    From Debian FTP Masters@21:1/5 to All on Sat Aug 24 17:40:01 2024
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    Format: 1.8
    Date: Sat, 24 Aug 2024 09:24:14 -0300
    Source: amd64-microcode
    Architecture: source
    Version: 3.20240820.1~deb12u1
    Distribution: bookworm
    Urgency: high
    Maintainer: Henrique de Moraes Holschuh <hmh@debian.org>
    Changed-By: Henrique de Moraes Holschuh <hmh@debian.org>
    Changes:
    amd64-microcode (3.20240820.1~deb12u1) bookworm; urgency=medium
    .
    * Rebuild for bookworm (revert merged-usr changes from unstable)
    .
    amd64-microcode (3.20240820.1) unstable; urgency=high
    .
    * Update package data from linux-firmware 20240820
    * New AMD-SEV firmware from AMD upstream (20240820)
    + Updated SEV firmware:
    Family 17h models 30h-3fh: version 0.24 build 20
    Family 19h models 00h-0fh: version 1.55 build 21
    Family 19h models 10h-1fh: version 1.55 build 37
    + New SEV firmware:
    Family 19h models a0h-afh: version 1.55 build 37
    * SECURITY UPDATE (AMD-SB-3003):
    * Mitigates CVE-2023-20584: IOMMU improperly handles certain special
    address ranges with invalid device table entries (DTEs), which may allow
    an attacker with privileges and a compromised Hypervisor to induce DTE
    faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of
    guest integrity.
    * Mitigates CVE-2023-31356: Incomplete system memory cleanup in SEV
    firmware could allow a privileged attacker to corrupt guest private
    memory, potentially resulting in a loss of data integrity. Checksums-Sha1:
    18c2470d6e023574315363fb03f8635c8a4ed331 1727 amd64-microcode_3.20240820.1~deb12u1.dsc
    af8c82dcc2de99f24b9231fcd59a018c2bcbf589 178476 amd64-microcode_3.20240820.1~deb12u1.tar.xz
    a7a3b7f15174bc3a9db16bbb84f1a8e747f7c638 6204 amd64-microcode_3.20240820.1~deb12u1_amd64.buildinfo
    Checksums-Sha256:
    304169d84329e3501e57d09a2c6e317311831267538b1a3d9d972eb224c67ded 1727 amd64-microcode_3.20240820.1~deb12u1.dsc
    349ab7217396b3bd6be0867dad6568f187889dab95914b04b3da4a68c96fb281 178476 amd64-microcode_3.20240820.1~deb12u1.tar.xz
    1c2514374d6f3f793ee3aa8bb409e580d60ff0edc4e0f520a6d57d2dd03eb25e 6204 amd64-microcode_3.20240820.1~deb12u1_amd64.buildinfo
    Files:
    6abd62148fda183f821ad81be3f3652c 1727 non-free-firmware/admin standard amd64-microcode_3.20240820.1~deb12u1.dsc
    fadda3560ced4e5a66015127c683177e 178476 non-free-firmware/admin standard amd64-microcode_3.20240820.1~deb12u1.tar.xz
    bd85651911f8b50430bada14f45edbfb 6204 non-free-firmware/admin standard amd64-microcode_3.20240820.1~deb12u1_amd64.buildinfo

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpvbMGUAhfu+gsYOwlOXoPKamj0cFAmbJ00EACgkQlOXoPKam j0c+IA/7BzPvA529Onz2T1/fOglcqAtGMpDsi5l2LEg28B7Xx5IC7o5ZLKBsymDq BiYNqkaaro9TYocW1K0Y36S4UJBrwXldVVORhRTYT5kP9t9/wmQokCmzpXRCabBS yMvdgbiKxQgiZzO44sRsT8cbyABnBMBefyhTsnRGp742Q7jCokhLwjl6zvxr+U5a nERTovHfKHMeK6NwXVHFYkao/C6OQ+nzyfejCbHKPeqGdpIxdruMLYh0BqZzt/Qo 9ZpYYWSPO3It1+/fvDROz7cPpCQChkNJ7M4W2bllxjzv9cnWEB3+MKRXKBAhy0ng 6pHSKmIh7rG4syHzZ0S6VReg7zS+hnE6/FNr2MG2pGyIIgo0B0JKva5F0iHPadl7 T81QjXA7E4ilQIdEn+YhdomJiwnTuylR6/cZ82/IFI1omHYTCY5u+MP6CFV9wVhD sPyIoSKp+Re4J6O956JTW4nS5yuPTK9XJJYp/NBP6kK6q5W6KRwf9P6cF4jtgfnK IfRLbi16rVSsOA6RcTO76Wrmybqw9KqVEpVKM2nwSp+UuCC5VV/nN+rXD1/Z6ElA 5IGWCuRpZBEz8ZOvmo9fkUo8loUDXmNR2bPvzZk7KbOb1aT58yoF7DgNAvqywtt5 GwS4VkM5s0FeCxDe/OoK5ct05aiVTM0BqManDjBZf8gTlYyKMDI=
    =nEmr
    -----END PGP SIGNATURE-----


    --==============G43062083193578275=Content-Type: application/pgp-signature

    -----BEGIN PGP SIGNATURE-----

    iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCZsn8+QAKCRCb9qggYcy5 IfVCAQCsUzkGg39ZuJlzk7/hTGg32qzs8aPPLOBTuCijVk/rFwD/R16QPIgo48r2 EGY5UK2PMluoZBXZtsIJUmGlw+oq5gAuCZ
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)