-
Notifications
You must be signed in to change notification settings - Fork 84
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
linux-firmware: update to 20230625+git20230724+debian20210818+1~bpo11+1 #4637
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approve with possible unknown regression in mind.
Dracut did not apply the microcode correctly. Changes pending. |
…+1; #4636 Addresses a use-after-free vulnerability in AMD Zen2 processors. Ref: https://lock.cmpxchg8b.com/zenbleed.html
a9316bd
to
1696891
Compare
Fix tested successfully (with Dracut caveats, saved for another topic) on @Icenowy's EPYC 7002; failed on @chenx97's Ryzen PRO 4750U; microcode update not available for @eatradish's Ryzen 3950X. ??? |
This fix might just be EPYC/Threadripper-specific. Sigh. Those chips were clearly affected. |
@Fearyncess: It may well be the case that AMD has yet to release fixes for all affected models. We will wait on this for another day. |
For MSDT (Ryzen 3000/4000 CPU Series), it maybe only have a BIOS update incl. updated AGESA with mitigations from mobo vendors, if AMD decided doesn't fix it by microcode update in linux-firmware. |
Unfortunately we'll wait til at least November for our beloved (and now annoying) consumer desktop processors to be patched properly. We should patch the kernel to set the chicken bit for us before such microcode update lands. |
To be addressed in #4789. Closing. |
Topic Description
This topic addresses a use-after-free vulnerability in AMD Zen2 processors. #4636
Ref: https://lock.cmpxchg8b.com/zenbleed.html
Package(s) Affected
firmware-free
v20230625+git20230724+debian20210818+1~bpo11+1firmware-nonfree
v20230625+git20230724+debian20210818+1~bpo11+1Security Update?
Yes, #4636
Build Order
Test Build(s) Done
Primary Architectures
noarch
Update(s) Uploaded to Stable
Primary Architectures
noarch