UbuntuUpdates.org

Package "amd64-microcode"

Name: amd64-microcode

Description:

Platform firmware and microcode for AMD CPUs and SoCs

Latest version: 3.20251202.1ubuntu0.25.10.1
Release: questing (25.10)
Level: updates
Repository: main

Links


Download "amd64-microcode"


Other versions of "amd64-microcode" in Questing

Repository Area Version
base main 3.20250708.1ubuntu1
security main 3.20251202.1ubuntu0.25.10.1

Changelog

Version: 3.20251202.1ubuntu0.25.10.1 2026-06-25 17:07:33 UTC

  amd64-microcode (3.20251202.1ubuntu0.25.10.1) questing-security; urgency=medium

  [ Henrique de Moraes Holschuh ]
  * Update package data from linux-firmware 20251202
    * ATTENTION: regression risk if backported to stable or LTS.
      The amd processor microcode updates in this release will not load on
      systems with outdated BIOS vulnerable to "Entrysign" unless a number of
      kernel patches are present.
    * amd-tee: update AMD PMF TA Firmware to v3.1.
    * amd-ucode: update with release 2025-12-02:
      + SECURITY UPDATE (AMD-SB-7055 / CVE-2025-62626)
        Fix RDSEED Failure on more AMD Zen 5 Processor models
        (closes: #1120005)
    * amd-ucode: update with release 2025-11-13:
      + SECURITY UPDATE (AMD-SB-7055 / CVE-2025-62626)
        Fix RDSEED Failure on more AMD Zen 5 Processor models
    * amd-ucode: update with release 2025-10-30:
      + SECURITY UPDATE (AMD-SB-7055 / CVE-2025-62626)
        Fix RDSEED Failure on some AMD Zen 5 Processor models
    + amd-ucode: update with release 2025-10-27:
      * This is the final microcode release for systems that have not
        been updated to fix vulnerability AMD-SB-7033 "Entrysign").
      * A kernel update is needed for the microcode driver to be able
        to select the appropriate microcode updates for outdated system
        firmware vulnerable to "Entrysign".
      * On non-updated kernels, this will potentially *regress* the
        microcode version on the running system back to the one in the
        (outdated, unpatched-for-Entrysign) BIOS.
    + amd-ucode: update with release 2025-07-29:
      + SECURITY UPDATE (AMD-SB-7029: CVE-2024-36350, CVE-2024-36357):
        Mitigate transient execution vulnerabilities in some AMD processors
        which might allow an attacker to infer data from previous stores
        (TSA-SQ) or data in the L1D cache (TSA-L1), potentially resulting in
        the leakage of privileged information and sensitive information across
        priviledged boundaries (closes: #1109035)
      * NOTE: Requires kernel and hypervisor changes for the security
        mitigations to be applied (issue VERW instruction at appropriate
        times).
  * initramfs: guard against copying non-microcode data into the
    early-initramfs bundle, for the benefit of those that copy all files from
    linux-firmware into /lib/firmware/*. Thanks to Eric Valette for tracking
    it down (closes: #1101350)
  * NEWS.Debian: update for post-Entrysign microcode updates
    Document that kernel patches are needed to avoid regressing the microcode
    release on vulnerable Zen2/3/4 systems (family 0x19), and also that these
    systems will not receive any future microcode updates.

  [ Rodrigo Figueiredo Zaiden ]
  * Remaining changes:
    - debian/initramfs.hook: initramfs-tools hook:
      + Default to 'early' instead of 'auto' when building with
        MODULES=most
      + Do not override preset defaults from auto-exported conf
        snippets loaded by initramfs-tools.
    - debian/control: Depend on 3cpio for the initramfs-tools hook.

 -- Rodrigo Figueiredo Zaiden <email address hidden> Tue, 23 Jun 2026 11:08:49 -0300

1120005 amd64-microcode: CVE-2025-62626
1109035 amd64-microcode: 2024-36350/TSA-SQ and CVE-2024-36357/TSA-L1
1101350 amd64-microcode: microcode update check keeps telling me I'm not using the latest microcode
CVE-2025-62626 Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, po
CVE-2024-36350 A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the lea
CVE-2024-36357 A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage



About   -   Send Feedback to @ubuntu_updates