[Bug 272695] sysutils/devcpu-data-amd: A new microcode attack against the AMD Zen uarch has been published

From: <bugzilla-noreply_at_freebsd.org>
Date: Mon, 24 Jul 2023 14:46:21 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=272695

            Bug ID: 272695
           Summary: sysutils/devcpu-data-amd: A new microcode attack
                    against the AMD Zen uarch has been published
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: Individual Port(s)
          Assignee: sbruno@FreeBSD.org
          Reporter: crest@rlwinm.de
          Assignee: sbruno@FreeBSD.org
             Flags: maintainer-feedback?(sbruno@FreeBSD.org)

A new attack on AMD Zen CPUs has just been published at
https://lock.cmpxchg8b.com/zenbleed.html. AMD has released a microcode updated
closing the exploitable vulnerability, but a workaround via cpuctl is possible
(probably with a higher performance penalty). Waiting for mainboard vendors to
release firmware updates including the updated microcode and users to install
it is unrealistic. This port should be the best delivery mechanism available to
FreeBSD users.

-- 
You are receiving this mail because:
You are the assignee for the bug.