From: Dave Hansen <dave.hansen@intel.com>
To: Andrew Cooper <andrew.cooper3@citrix.com>, dave.hansen@linux.intel.com
Cc: bp@alien8.de, linux-kernel@vger.kernel.org, tglx@linutronix.de,
x86@kernel.org
Subject: Re: [RFC][PATCH] x86/cpu/bugs: Consider having old Intel microcode to be a vulnerability
Date: Tue, 12 Nov 2024 09:15:05 -0800 [thread overview]
Message-ID: <001092d4-8431-488b-a98d-3aa5d4ecb692@intel.com> (raw)
In-Reply-To: <59718ea7-efab-4975-a4e8-89c1d114a2e5@citrix.com>
On 11/8/24 15:36, Andrew Cooper wrote:
>> You can't practically run old microcode and consider a system secure
>> these days. So, let's call old microcode what it is: a vulnerability.
>
> The list becomes stale 4 times a year, so you need to identify when it's
> out of date, and whatever that something is has to be strong enough to
> cause distros to backport too. Perhaps a date in the header, so you can
> at least report "status vulnerable, metadata out of date".
I don't want to get too fancy about this. I'm assuming that mainline
and the stable kernels will be regularly fed new metadata. The only way
to have out-of-date metadata should be by running an out-of-date kernel
in which case you have bigger problems on your hands.
> Also, you want to identify EOL CPUs. Just because they're on the most
> recent published ucode doesn't mean they're not vulnerable.
That's a good idea too. But I think it deserves a separate discussion
and separate patch.
> Under some hypervisors, you get fed the revision 0x7fffffff. Others
> might tell you the truth, or it may be the truth from when you booted.
> For this, probably best to say "consult your hypervisor".
Good point. We should probably just say "unknown" when running as a
guest, or just not have the sysfs file at all.
> Failure to publish information, or not publishing fixes for in-support
> parts should be considered a vulnerability. (*ahem*, AMD)
>
> Or you could just simplify the whole path to "yes". It's true, even if
> people don't know.
This series answers the question:
Has the vendor published a newer OS-loadable microcode than you
are running right now?
It doesn't seek to answer the question:
Is the microcode that you are running right now vulnerable to
anything (that the kernel knows about)?
I think the first question is quite answerable in a pretty factual way.
The second question is much hardware. It's worth answering for sure ...
with another patch. :)
next prev parent reply other threads:[~2024-11-12 17:15 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-07 17:06 Dave Hansen
2024-11-08 23:36 ` Andrew Cooper
2024-11-12 17:15 ` Dave Hansen [this message]
2024-11-12 6:37 ` Alex Murray
2024-11-12 15:51 ` Dave Hansen
2024-11-13 3:29 ` Alex Murray
2024-11-13 16:00 ` Dave Hansen
2024-11-13 23:58 ` Alex Murray
2024-11-14 0:37 ` Dave Hansen
2024-11-18 8:35 ` Alex Murray
2024-11-13 9:28 ` Nikolay Borisov
2024-11-14 2:09 ` Andrew Cooper
2024-11-18 20:02 ` Dave Hansen
2024-11-19 17:45 ` Pawan Gupta
2024-11-19 18:49 ` Dave Hansen
2024-11-19 19:31 ` Pawan Gupta
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=001092d4-8431-488b-a98d-3aa5d4ecb692@intel.com \
--to=dave.hansen@intel.com \
--cc=andrew.cooper3@citrix.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®