Important: linux-firmware security, bug fix, and enhancement update
The linux-firmware packages contain all of the firmware files that are required by various devices to operate. Security Fix(es): * hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi (CVE-2022-27635) * hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi (CVE-2022-40964) * hw: intel: Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi (CVE-2022-46329) * hw: intel: Improper input validation in some Intel(R) PROSet/Wireless WiFi (CVE-2022-36351) * hw amd: Return Address Predictor vulnerability leading to information disclosure (CVE-2023-20569) * hw: intel: Improper input validation in some Intel(R) PROSet/Wireless WiFi (CVE-2022-38076) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The linux-firmware packages contain all of the firmware files that are required by various devices to operate. Security Fix(es): * hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi (CVE-2022-27635) * hw: intel: Improper access control for some Intel(R) PROSet/Wireless WiFi (CVE-2022-40964) * hw: intel: Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi (CVE-2022-46329) * hw: intel: Improper input validation in some Intel(R) PROSet/Wireless WiFi (CVE-2022-36351) * hw amd: Return Address Predictor vulnerability leading to information disclosure (CVE-2023-20569) * hw: intel: Improper input validation in some Intel(R) PROSet/Wireless WiFi (CVE-2022-38076) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2023:6595
- https://access.redhat.com/security/cve/CVE-2022-27635
- https://access.redhat.com/security/cve/CVE-2022-36351
- https://access.redhat.com/security/cve/CVE-2022-38076
- https://access.redhat.com/security/cve/CVE-2022-40964
- https://access.redhat.com/security/cve/CVE-2022-46329
- https://access.redhat.com/security/cve/CVE-2023-20569
- https://bugzilla.redhat.com/2207625
- https://bugzilla.redhat.com/2238960
- https://bugzilla.redhat.com/2238961
- https://bugzilla.redhat.com/2238962
- https://bugzilla.redhat.com/2238963
- https://bugzilla.redhat.com/2238964
- https://errata.almalinux.org/9/ALSA-2023-6595.html