Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

linux-firmware: update to 20230625+git20230724+debian20210818+1~bpo11+1 #4637

Closed
wants to merge 1 commit into from

Conversation

MingcongBai
Copy link
Member

Topic Description

This topic addresses a use-after-free vulnerability in AMD Zen2 processors. #4636

Ref: https://lock.cmpxchg8b.com/zenbleed.html

Package(s) Affected

  • firmware-free v20230625+git20230724+debian20210818+1~bpo11+1
  • firmware-nonfree v20230625+git20230724+debian20210818+1~bpo11+1

Security Update?

Yes, #4636

Build Order

linux-firmware

Test Build(s) Done

Primary Architectures

  • Architecture-independent noarch

Update(s) Uploaded to Stable

Primary Architectures

  • Architecture-independent noarch

@MingcongBai MingcongBai added upgrade Topic/issue involves a package upgrade security Topic/issue involves a security issue/fixed priority High-priority issue/topic 0day Topic/issue involves a 0-day security issue and must be addressed immediately labels Jul 24, 2023
KexyBiscuit
KexyBiscuit previously approved these changes Jul 24, 2023
Copy link
Member

@KexyBiscuit KexyBiscuit left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve with possible unknown regression in mind.

@MingcongBai
Copy link
Member Author

Dracut did not apply the microcode correctly. Changes pending.

…+1; #4636

Addresses a use-after-free vulnerability in AMD Zen2 processors.

Ref: https://lock.cmpxchg8b.com/zenbleed.html
@MingcongBai
Copy link
Member Author

Fix tested successfully (with Dracut caveats, saved for another topic) on @Icenowy's EPYC 7002; failed on @chenx97's Ryzen PRO 4750U; microcode update not available for @eatradish's Ryzen 3950X. ???

@MingcongBai
Copy link
Member Author

This fix might just be EPYC/Threadripper-specific. Sigh.

Those chips were clearly affected.

@MingcongBai
Copy link
Member Author

@Fearyncess: It may well be the case that AMD has yet to release fixes for all affected models.

We will wait on this for another day.

@Fearyncess
Copy link
Member

@Fearyncess: It may well be the case that AMD has yet to release fixes for all affected models.

We will wait on this for another day.

For MSDT (Ryzen 3000/4000 CPU Series), it maybe only have a BIOS update incl. updated AGESA with mitigations from mobo vendors, if AMD decided doesn't fix it by microcode update in linux-firmware.

@chenx97
Copy link
Member

chenx97 commented Jul 25, 2023

Unfortunately we'll wait til at least November for our beloved (and now annoying) consumer desktop processors to be patched properly. We should patch the kernel to set the chicken bit for us before such microcode update lands.

@MingcongBai
Copy link
Member Author

To be addressed in #4789. Closing.

@MingcongBai MingcongBai closed this Nov 7, 2023
@jiegec jiegec deleted the linux-firmware-20230724 branch March 18, 2024 11:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
0day Topic/issue involves a 0-day security issue and must be addressed immediately priority High-priority issue/topic security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants