Bug 1141035 - (CVE-2019-11139) VUL-0: CVE-2019-11139: kernel: voltage modulation
(CVE-2019-11139)
VUL-0: CVE-2019-11139: kernel: voltage modulation
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Jiri Kosina
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-10 15:08 UTC by Marcus Meissner
Modified: 2019-11-28 20:13 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marcus Meissner 2019-10-04 07:06:41 UTC
microcode only fixes
Comment 5 Swamp Workflow Management 2019-11-13 00:04:23 UTC
SUSE-SU-2019:2959-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1139073,1141035,1154043,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    ucode-intel-20191112-13.53.1
SUSE OpenStack Cloud 8 (src):    ucode-intel-20191112-13.53.1
SUSE OpenStack Cloud 7 (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server 12-SP5 (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server 12-SP4 (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    ucode-intel-20191112-13.53.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    ucode-intel-20191112-13.53.1
SUSE Enterprise Storage 5 (src):    ucode-intel-20191112-13.53.1
SUSE CaaS Platform 3.0 (src):    ucode-intel-20191112-13.53.1
HPE Helion Openstack 8 (src):    ucode-intel-20191112-13.53.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Swamp Workflow Management 2019-11-13 00:21:31 UTC
SUSE-SU-2019:2958-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    ucode-intel-20191112-3.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2019-11-13 01:02:21 UTC
SUSE-SU-2019:2957-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE Linux Enterprise Module for Basesystem 15 (src):    ucode-intel-20191112-3.28.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Marcus Meissner 2019-11-13 15:08:53 UTC
This issue is not related to the SUSE OS itself, but delivered only via Intel Microcode updates.
Comment 12 Swamp Workflow Management 2019-11-13 20:17:08 UTC
SUSE-SU-2019:14217-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    microcode_ctl-1.17-102.83.47.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    microcode_ctl-1.17-102.83.47.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2019-11-14 11:12:40 UTC
openSUSE-SU-2019:2504-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
openSUSE Leap 15.0 (src):    ucode-intel-20191112-lp150.2.30.1
Comment 14 Swamp Workflow Management 2019-11-14 14:11:37 UTC
openSUSE-SU-2019:2509-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
openSUSE Leap 15.1 (src):    ucode-intel-20191112-lp151.2.9.1
Comment 15 Swamp Workflow Management 2019-11-15 17:12:35 UTC
SUSE-SU-2019:2988-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    ucode-intel-20191112a-13.56.1
SUSE OpenStack Cloud 8 (src):    ucode-intel-20191112a-13.56.1
SUSE OpenStack Cloud 7 (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server 12-SP4 (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    ucode-intel-20191112a-13.56.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    ucode-intel-20191112a-13.56.1
SUSE Enterprise Storage 5 (src):    ucode-intel-20191112a-13.56.1
SUSE CaaS Platform 3.0 (src):    ucode-intel-20191112a-13.56.1
HPE Helion Openstack 8 (src):    ucode-intel-20191112a-13.56.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2019-11-15 17:13:35 UTC
SUSE-SU-2019:2986-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE Linux Enterprise Module for Basesystem 15 (src):    ucode-intel-20191112a-3.31.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2019-11-15 17:14:30 UTC
SUSE-SU-2019:2987-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP1 (src):    ucode-intel-20191112a-3.13.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Swamp Workflow Management 2019-11-15 17:15:26 UTC
SUSE-SU-2019:14220-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    microcode_ctl-1.17-102.83.50.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    microcode_ctl-1.17-102.83.50.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 19 Swamp Workflow Management 2019-11-18 14:12:35 UTC
openSUSE-SU-2019:2528-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
openSUSE Leap 15.1 (src):    ucode-intel-20191112a-lp151.2.12.1
Comment 20 Swamp Workflow Management 2019-11-18 14:14:10 UTC
openSUSE-SU-2019:2527-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
openSUSE Leap 15.0 (src):    ucode-intel-20191112a-lp150.2.33.1
Comment 22 Swamp Workflow Management 2019-11-28 20:13:47 UTC
SUSE-SU-2019:3091-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1139073,1141035,1155988,1157004
CVE References: CVE-2019-11135,CVE-2019-11139
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    ucode-intel-20191115-3.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.