On Fri, Jan 12, 2018 at 3:31 PM, Chris Murphy <li...@colorremedies.com> wrote:
> Koji contains linux-firmware-20171215-82.git2451bb22.fc27 which
> contains intel-ucode from 20171117. But I don't know if this firmware
> contains the microcode required to completely secure from Spectre
> variant 2.

Intel CPU microcode is not provided by the linux-firmware package.  It
is shipped in the microcode_ctl package.

Did you actually find intel-ucode in linux-firmware or were you just
assuming that is where it was coming from?  I'm asking to make sure it
was a misunderstanding because others might make the same mistake.

> https://access.redhat.com/articles/3311301
> "This vulnerability requires both updated microcode and kernel patches"
>
> Intel has released microcode 20180108, but there are no builds in koji
> yet for this version so I manually applied them from
> https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File
>
> and also updated the initramfs with dracut -f so the change is
> persistent. This does change the microcode on my laptop compared to
> the Fedora supplied microcode.

https://bodhi.fedoraproject.org/updates/FEDORA-2018-7e17849364

josh
_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Reply via email to