[RHSA-2023:6595] linux-firmware security, bug fix, and enhancement update

Severity Important
Affected Packages 17
CVEs 6

The linux-firmware packages contain all of the firmware files that are required by various devices to operate.

Security Fix(es):

  • hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi (CVE-2022-27635)

  • hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi (CVE-2022-40964)

  • hw: intel: Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi (CVE-2022-46329)

  • hw: intel: Improper input validation in some Intel(R) PROSet/Wireless WiFi (CVE-2022-36351)

  • hw amd: Return Address Predictor vulnerability leading to information disclosure (CVE-2023-20569)

  • hw: intel: Improper input validation in some Intel(R) PROSet/Wireless WiFi (CVE-2022-38076)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.3 Release Notes linked from the References section.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/netronome-firmware?distro=redhat-9.3 redhat netronome-firmware < 20230814-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/linux-firmware?distro=redhat-9.3 redhat linux-firmware < 20230814-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/linux-firmware-whence?distro=redhat-9.3 redhat linux-firmware-whence < 20230814-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/libertas-sd8787-firmware?distro=redhat-9.3 redhat libertas-sd8787-firmware < 20230814-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl7260-firmware?distro=redhat-9.3 redhat iwl7260-firmware < 25.30.13.0-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl6050-firmware?distro=redhat-9.3 redhat iwl6050-firmware < 41.28.5.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl6000g2b-firmware?distro=redhat-9.3 redhat iwl6000g2b-firmware < 18.168.6.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl6000g2a-firmware?distro=redhat-9.3 redhat iwl6000g2a-firmware < 18.168.6.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl5150-firmware?distro=redhat-9.3 redhat iwl5150-firmware < 8.24.2.2-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl5000-firmware?distro=redhat-9.3 redhat iwl5000-firmware < 8.83.5.1_1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl3160-firmware?distro=redhat-9.3 redhat iwl3160-firmware < 25.30.13.0-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl2030-firmware?distro=redhat-9.3 redhat iwl2030-firmware < 18.168.6.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl2000-firmware?distro=redhat-9.3 redhat iwl2000-firmware < 18.168.6.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl135-firmware?distro=redhat-9.3 redhat iwl135-firmware < 18.168.6.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl105-firmware?distro=redhat-9.3 redhat iwl105-firmware < 18.168.6.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl1000-firmware?distro=redhat-9.3 redhat iwl1000-firmware < 39.31.5.1-140.el9_3 redhat-9.3
Affected pkg:rpm/redhat/iwl100-firmware?distro=redhat-9.3 redhat iwl100-firmware < 39.31.5.1-140.el9_3 redhat-9.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...