diff --git a/issues/CVE-2023-23583/index.html b/issues/CVE-2023-23583/index.html index fc49715..2c01528 100644 --- a/issues/CVE-2023-23583/index.html +++ b/issues/CVE-2023-23583/index.html @@ -607,7 +607,7 @@ -

Please refer to our override package of microcode_ctl.

+

Please refer to our override package of microcode_ctl.

EL8

-

Besides the upstream fix, we also retained the mitigation in our override package of glibc.

+

Besides the upstream fix, we also retained the mitigation in our override package of glibc.

EL8

Known-effective vulnerability mitigations and fixes

-

2.34-60.el9_2.security.0.2 included mitigations sufficient to avoid security exposure of CVE-2023-4911 and a backport of upstream glibc fix of CVE-2023-4527 that was not yet in upstream EL. In the update to 2.34-60.7.el9_2.security.0.3, we retained the mitigations while rebasing on upstream EL's package with upstream fixes for these vulnerabilities (and more).

+

2.34-60.el9_2.security.0.2 included mitigations sufficient to avoid security exposure of CVE-2023-4911 and a backport of upstream glibc fix of CVE-2023-4527 that was not yet in upstream EL. In the update to 2.34-60.7.el9_2.security.0.3, we retained the mitigations while rebasing on upstream EL's package with upstream fixes for these vulnerabilities (and more).

In general, inclusion of additional security fixes will be "reverted" if and when those get included in upstream EL packages that we rebase our changes on.

Change log

* Fri Oct  6 2023 Solar Designer <solar@openwall.com> - 2.34-60.7.el9.security.0.3
@@ -673,7 +673,7 @@
   
     
       Last update:
-      October 13, 2023
+      November 15, 2023
       
     
   
diff --git a/packages/microcode_ctl/index.html b/packages/microcode_ctl/index.html
index 97058b1..8aca6c3 100644
--- a/packages/microcode_ctl/index.html
+++ b/packages/microcode_ctl/index.html
@@ -599,7 +599,7 @@
 
 

Changes summary

    -
  • Update Intel CPU microcode to microcode-20231114 (fixes CVE-2023-23583), temporarily dropping most documentation patches
  • +
  • Update Intel CPU microcode to microcode-20231114 (fixes CVE-2023-23583), temporarily dropping most documentation patches

Change log

* Tue Nov 14 2023 Solar Designer <solar@openwall.com> - 4:20231114-1
diff --git a/sitemap.xml.gz b/sitemap.xml.gz
index 145f2b1..3acf87c 100644
Binary files a/sitemap.xml.gz and b/sitemap.xml.gz differ