git: 520254a6f1 - main - Update EN-26:20.microcode to split 15.x and 14.x.
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 27 Aug 2026 19:02:23 UTC
The branch main has been updated by gordon:
URL: https://cgit.FreeBSD.org/doc/commit/?id=520254a6f1088e13eef57e7808dbfb9603018a21
commit 520254a6f1088e13eef57e7808dbfb9603018a21
Author: Gordon Tetlow <gordon@FreeBSD.org>
AuthorDate: 2026-08-27 18:59:02 +0000
Commit: Gordon Tetlow <gordon@FreeBSD.org>
CommitDate: 2026-08-27 18:59:02 +0000
Update EN-26:20.microcode to split 15.x and 14.x.
The 14.x patch required one additional commit to be included. Regenerate
and split the patches into major version specific patches.
Add Revision History to EN text and the two different patch URLs.
Reported by: David Cross
Approved by: so
---
.../advisories/FreeBSD-EN-26:20.microcode.asc | 45 +++---
.../security/patches/EN-26:20/microcode-14.patch | 168 +++++++++++++++++++++
.../patches/EN-26:20/microcode-14.patch.asc | 17 +++
.../{microcode.patch => microcode-15.patch} | 0
...{microcode.patch.asc => microcode-15.patch.asc} | 0
5 files changed, 213 insertions(+), 17 deletions(-)
diff --git a/website/static/security/advisories/FreeBSD-EN-26:20.microcode.asc b/website/static/security/advisories/FreeBSD-EN-26:20.microcode.asc
index 1720320815..c5ad40f0bf 100644
--- a/website/static/security/advisories/FreeBSD-EN-26:20.microcode.asc
+++ b/website/static/security/advisories/FreeBSD-EN-26:20.microcode.asc
@@ -22,6 +22,11 @@ Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.
+0. Revision History
+
+v1.0 - 2026-08-25 -- Initial revision
+v1.1 - 2026-08-27 -- Split patches for 15.x and 14.x due to missed commit
+
I. Background
Modern x86 CPUs support updates to their microcode. FreeBSD can apply these
@@ -136,9 +141,15 @@ FreeBSD release branches.
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.
-# fetch https://security.FreeBSD.org/patches/EN-26:20/microcode.patch
-# fetch https://security.FreeBSD.org/patches/EN-26:20/microcode.patch.asc
-# gpg --verify microcode.patch.asc
+[FreeBSD 15.x]
+# fetch https://security.FreeBSD.org/patches/EN-26:20/microcode-15.patch
+# fetch https://security.FreeBSD.org/patches/EN-26:20/microcode-15.patch.asc
+# gpg --verify microcode-15.patch.asc
+
+[FreeBSD 14.x]
+# fetch https://security.FreeBSD.org/patches/EN-26:20/microcode-14.patch
+# fetch https://security.FreeBSD.org/patches/EN-26:20/microcode-14.patch.asc
+# gpg --verify microcode-14.patch.asc
b) Apply the patch. Execute the following commands as root:
@@ -185,18 +196,18 @@ The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-26:20.microcode.asc>
-----BEGIN PGP SIGNATURE-----
-iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmqN3XAbFIAAAAAABAAO
-bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvse4P/isqmBRUFLLUnVFS/AD7
-Wlg20e54L4CRORCqhL1p33WdcKs6bHg7Tgvutwy23HmX9ISrOanm5WkFq2qN16qc
-olNJDvlXHLeIseDH6WQrxWiBooYqqJpLOJyolqB+R0TIGRvRMidbdM24gHyOCWST
-MvraPYkqkQH9DSO1CYUHoLTcVLek/l9ux1p2WApHSqOw7GPcltiYUnyvKrOqBxYs
-DD4n0GIw0JfsXK1L9MLXJILjROUpItDHnv1CsG8VVaWQI0c+5826dTVoFsDQ1RUc
-mcIiBiWP/gmKxl48wzjq9qZccGN2vHMLrFYA0Zu/syqpB2g5b0zQbm9iKIak+YIJ
-mKHTUGAZ0YJpQAXf8f1q+pED91Veh9k0fIvnSwsDa2dfgk2XMfZeWIyHbddxS0p6
-fvnCroT4sMvequ2wpC64jpebASmwjiZYYY9gPk2TdgOlu83PnYUkMbT4gv5RHgIo
-qwK7WQ2bDO3GaRHGQ3Zfo/Dl97bGg6KDDZZEbFOBv9hWu2bKgmLMvo2HtgKGGLDa
-UBGypDYWC0abbtbaqTBFtJsvUbcpf6llG/lJT6YaipVrqBjLyNFJhETS1zNIQQSr
-Y8pvUc+tsqlLmrI4AaqcvIwC0OY6ATppQ49ZMpujaDf3nj9wG9vw6d1l12kIWjEE
-0XE3NnDLvAne7G2cC+ktwGzB
-=KmJ4
+iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmqQiB0bFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvqg8P+wSA96Z9Lx3voJpcGcWf
+DQG8AB/17xx8vU6Vvc4yEGUnVlglEIPKbpMQxVBirF+HDOYvkjTcmRF4NDQUz04T
+5zcZiRVbc06k1+U+guEYmlOB7LqBfBaU+j/67bxK1ZVtCOg3N5zJjQsRlTzJ5Ip6
+xFZuwdbD1VMy+RVwXgllb9XKqdNdqBF1/ULyqhI3HhqWYJC7mdWAw9616SaeLYl7
+qydBkdXF8DIiEriwB96g609W8Xu3+9gghnce3tYKEPKietGidsqdl0PAEoHTW2JE
+LI83M+9p1URJEauoVMvbVARrDv0KTASuBgRFehNipqoHruFusTrmQqekKp7IqDXI
+SYBaJC1j7QIRStAcR9mTQ/8YFxRD7p22ydlGrhDt4SqtIUGZ1L1geEIQBI36/nZs
+fX96aZq5AW1Fr30723W9dLarsRkEaNvARPF91CXmn19oPqpmKVEfi6Lf6rqNskak
+o3oij3YZYNat8meB598BGvjPun99f6oVFABkipHIMzsnt4d+k1sA3t7LCjImABLW
+Sqhtf2l3EHAatVDgCz7iAGV0ydr3ljnsNLRQdPjmZ6JStYQUCI5D1+cBzx/yS9vD
++EhKNbuPXkTxaQy9kVlpQuAtN7gLnV2vf3YkjfgsuK2pvpSTRWC1/JSB+XNJWL8T
+24unZWhJ+n2bp5t8rdUnw527
+=AAwg
-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-26:20/microcode-14.patch b/website/static/security/patches/EN-26:20/microcode-14.patch
new file mode 100644
index 0000000000..1eb51a5325
--- /dev/null
+++ b/website/static/security/patches/EN-26:20/microcode-14.patch
@@ -0,0 +1,168 @@
+--- sys/x86/include/ucode.h.orig
++++ sys/x86/include/ucode.h
+@@ -56,7 +56,7 @@
+ } entries[0];
+ };
+
+-int ucode_intel_load(void *data, bool unsafe,
++int ucode_intel_load(const void *data, bool unsafe,
+ uint64_t *nrevp, uint64_t *orevp);
+ size_t ucode_load_bsp(uintptr_t free);
+ void ucode_load_ap(int cpu);
+--- sys/x86/x86/ucode.c.orig
++++ sys/x86/x86/ucode.c
+@@ -51,14 +51,14 @@
+ #include <vm/vm_kern.h>
+ #include <vm/vm_param.h>
+
+-static void *ucode_intel_match(uint8_t *data, size_t *len);
+-static int ucode_intel_verify(struct ucode_intel_header *hdr,
++static const void *ucode_intel_match(const uint8_t *data, size_t *len);
++static int ucode_intel_verify(const struct ucode_intel_header *hdr,
+ size_t resid);
+
+ static struct ucode_ops {
+ const char *vendor;
+- int (*load)(void *, bool, uint64_t *, uint64_t *);
+- void *(*match)(uint8_t *, size_t *);
++ int (*load)(const void *, bool, uint64_t *, uint64_t *);
++ const void *(*match)(const uint8_t *, size_t *);
+ } loaders[] = {
+ {
+ .vendor = INTEL_VENDOR_ID,
+@@ -68,8 +68,8 @@
+ };
+
+ /* Selected microcode update data. */
+-static void *early_ucode_data;
+-static void *ucode_data;
++static const void *early_ucode_data;
++static const void *ucode_data;
+ static struct ucode_ops *ucode_loader;
+
+ /* Variables used for reporting success or failure. */
+@@ -104,7 +104,7 @@
+ SYSINIT(ucode_log, SI_SUB_CPU, SI_ORDER_FIRST, log_msg, NULL);
+
+ int
+-ucode_intel_load(void *data, bool unsafe, uint64_t *nrevp, uint64_t *orevp)
++ucode_intel_load(const void *data, bool unsafe, uint64_t *nrevp, uint64_t *orevp)
+ {
+ uint64_t nrev, orev;
+ uint32_t cpuid[4];
+@@ -141,9 +141,10 @@
+ }
+
+ static int
+-ucode_intel_verify(struct ucode_intel_header *hdr, size_t resid)
++ucode_intel_verify(const struct ucode_intel_header *hdr, size_t resid)
+ {
+- uint32_t cksum, *data, size;
++ const uint32_t *data;
++ uint32_t cksum, size;
+ int i;
+
+ if (resid < sizeof(struct ucode_intel_header))
+@@ -161,7 +162,7 @@
+ return (1);
+
+ cksum = 0;
+- data = (uint32_t *)hdr;
++ data = (const uint32_t *)hdr;
+ for (i = 0; i < size / sizeof(uint32_t); i++)
+ cksum += data[i];
+ if (cksum != 0)
+@@ -169,16 +170,15 @@
+ return (0);
+ }
+
+-static void *
+-ucode_intel_match(uint8_t *data, size_t *len)
++static const void *
++ucode_intel_match(const uint8_t *data, size_t *len)
+ {
+- struct ucode_intel_header *hdr;
+- struct ucode_intel_extsig_table *table;
+- struct ucode_intel_extsig *entry;
++ const struct ucode_intel_header *hdr;
++ const struct ucode_intel_extsig_table *table;
++ const struct ucode_intel_extsig *entry;
+ uint64_t platformid;
+ size_t resid;
+ uint32_t data_size, flags, regs[4], sig, total_size;
+- int i;
+
+ do_cpuid(1, regs);
+ sig = regs[0];
+@@ -187,7 +187,7 @@
+ flags = 1 << ((platformid >> 50) & 0x7);
+
+ for (resid = *len; resid > 0; data += total_size, resid -= total_size) {
+- hdr = (struct ucode_intel_header *)data;
++ hdr = (const struct ucode_intel_header *)data;
+ if (ucode_intel_verify(hdr, resid) != 0) {
+ ucode_error = VERIFICATION_FAILED;
+ break;
+@@ -200,19 +200,35 @@
+ if (total_size == 0)
+ total_size = UCODE_INTEL_DEFAULT_DATA_SIZE +
+ sizeof(struct ucode_intel_header);
+- if (data_size > total_size + sizeof(struct ucode_intel_header))
+- table = (struct ucode_intel_extsig_table *)
+- ((uint8_t *)(hdr + 1) + data_size);
++
++ if (total_size > data_size + sizeof(struct ucode_intel_header))
++ table = (const struct ucode_intel_extsig_table *)
++ ((const uint8_t *)(hdr + 1) + data_size);
+ else
+ table = NULL;
+
+- if (hdr->processor_signature == sig) {
+- if ((hdr->processor_flags & flags) != 0) {
+- *len = data_size;
+- return (hdr + 1);
++ if (hdr->processor_signature == sig &&
++ (hdr->processor_flags & flags) != 0) {
++ *len = data_size;
++ return (hdr + 1);
++ }
++ if (table != NULL) {
++ size_t extsize;
++
++ extsize = total_size -
++ (data_size + sizeof(struct ucode_intel_header));
++ if (extsize < sizeof(struct ucode_intel_extsig_table)) {
++ ucode_error = VERIFICATION_FAILED;
++ break;
+ }
+- } else if (table != NULL) {
+- for (i = 0; i < table->signature_count; i++) {
++ extsize -= sizeof(struct ucode_intel_extsig_table);
++ for (uint32_t i = 0; i < table->signature_count; i++) {
++ if (extsize < sizeof(struct ucode_intel_extsig)) {
++ ucode_error = VERIFICATION_FAILED;
++ goto out;
++ }
++ extsize -= sizeof(struct ucode_intel_extsig);
++
+ entry = &table->entries[i];
+ if (entry->processor_signature == sig &&
+ (entry->processor_flags & flags) != 0) {
+@@ -222,6 +238,7 @@
+ }
+ }
+ }
++out:
+ return (NULL);
+ }
+
+@@ -318,7 +335,8 @@
+ uint32_t regs[4];
+ char vendor[13];
+ } cpuid;
+- uint8_t *addr, *fileaddr, *match;
++ const uint8_t *fileaddr, *match;
++ uint8_t *addr;
+ char *type;
+ uint64_t nrev, orev;
+ caddr_t file;
diff --git a/website/static/security/patches/EN-26:20/microcode-14.patch.asc b/website/static/security/patches/EN-26:20/microcode-14.patch.asc
new file mode 100644
index 0000000000..33912c2d7e
--- /dev/null
+++ b/website/static/security/patches/EN-26:20/microcode-14.patch.asc
@@ -0,0 +1,17 @@
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAABCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmqQhvIbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvrNUQALl25DoTG6AIm6V4fyzT
+M1ZjDhPk6QeafcmOs8o1Go3M+jqmIeuy7/PU9TblTkoM+8QD+PoDiLeGCer6aKZD
+vIvcSnxAkUluRFnZn9CvV5yT3XRTHz/O7VOkZGsEUl+f5RRnToTLMe8k0jaJCWnm
+Lq+gRZBA68N4hwrdNw4LwdbUVpsPo6GmNjTo2Wf7vEGVyOXuyEtusVZH4PzgXrdL
+qhuDyREjI0ZkO/tTs0OlYeZyQ6IXNExR6JTOs7TIXAbhIDbT7LRTt7xWNpfK1LEx
+QRkijbExsMrY4K5DgpDSWBMgsEH343jaHwZ0yR4GVE60O+I7HI/w5ACtr16kJO/p
+CY6lhnq+CPZAfF36BlMiftrT+7m6MH7lvtpw78gLt+Gmff9V8HWWMyc5FV7EuUtk
+66LbolhQ+HMzC3jAkfBHQE+uBF+Y6RZOL0ckxo+Pki9eqLufGw7kUP7ej9VUNgoE
+doy+5hAuhj0FWHYQkKu0FFdHg8GbE2/7nv3uAZVmTFUHnsvZBLRHxCIVZT7eHhuM
+tUKm2IS6xb6pP/tuT6SV1b0ZkU7bbB5QTsheHxEKB948pyZOybJOWXbhRwztnWdW
+hUVACdt+Iotjm/aug6g7X9UUWw82PXyg6EhLRoP8eLYM/kt5SBmSlSmBocCSaEtc
+XdmIyzmjJii8Fr1gGhhjGTG6
+=zZo4
+-----END PGP SIGNATURE-----
diff --git a/website/static/security/patches/EN-26:20/microcode.patch b/website/static/security/patches/EN-26:20/microcode-15.patch
similarity index 100%
rename from website/static/security/patches/EN-26:20/microcode.patch
rename to website/static/security/patches/EN-26:20/microcode-15.patch
diff --git a/website/static/security/patches/EN-26:20/microcode.patch.asc b/website/static/security/patches/EN-26:20/microcode-15.patch.asc
similarity index 100%
rename from website/static/security/patches/EN-26:20/microcode.patch.asc
rename to website/static/security/patches/EN-26:20/microcode-15.patch.asc