From nobody Mon Apr 15 14:19:01 2024 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4VJ8Rs35Qxz5GghF for ; Mon, 15 Apr 2024 14:19:05 +0000 (UTC) (envelope-from man130117@outlook.com) Received: from EUR04-VI1-obe.outbound.protection.outlook.com (mail-vi1eur04olkn2028.outbound.protection.outlook.com [40.92.75.28]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.protection.outlook.com", Issuer "DigiCert Cloud Services CA-1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4VJ8Rs0C83z4cfZ for ; Mon, 15 Apr 2024 14:19:04 +0000 (UTC) (envelope-from man130117@outlook.com) Authentication-Results: mx1.freebsd.org; none ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=VuYdASxa5IwjjONfii987/gibr56c2UDouT5Mf1TqWG89v7qOtUJS0qXuADjSygRqofj1bYPRxUSm3XiXPrExsuNolqg8x9diuGozMx5EppPBMDXQ2jKXEWPgE5tTRi/25BRxYwlFhxwbOEGZl9QWFg0AneWZ1FfxtPERVJmBVpwYq4YY2dOaqYLkwX08ArJQJ+bKiDDd6Ms9XM1CBE93X3lzxfQ8qLLmXW0sFjkZeBaN/F8ljyRUwvqQazf1fNmx0YFz6KE5hW2gwz5IuNz0+vGcx9ml5VPSnY17zyF8Ua0q/AoMDZb2yhy5gwnUs9YQyP9Cici6aHatq4NQ9NBAg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=vU7IBTmq/ZA7CLrYNx3vv9b/0QYfelTiTAuBAzJwDxI=; b=OTmDt0dfoAbg9yddG0GIxxYLwZBA2iYoxLNkR0XaoqHbZkf+uKSkE521vIxDOC+Hh5daB5TfZFGxl76DXtZqwPjCNmOOJGjR0mLkODZghdFHW30JSaGTr7+p4dL4921RoWs/fyB5GpldTeyhKPMxkUrcQaH44O89B7hsehVR9Kg4qP/+ybaOt3EF3ZgxVW+BpJ81bctH0FfTHUKCR9Odbv+irIIUQVgU03UpIAEa/HOJU2j/jHAuPLNw1X1IWBQMmEgCt03AzsJu0V81sap+HWEVhxec+4WFm9y66uLXwsGk+kITD9seEYtvr8YJD0/eHeHX6aWTvFfrw2nnHbh5uA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=outlook.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=vU7IBTmq/ZA7CLrYNx3vv9b/0QYfelTiTAuBAzJwDxI=; b=SjI10UOmPw3mKMncOZcDHWr1fdr/w2K5tgxb1Qee9y55/VZi71TwXyB82r26wecWhWscqMYimDWYvfN3n5GDsE5FgnNrJ/YNoiFiPgYIKzzw6d7obD4kDQmXJ1Eafrab1Ltagl442UbdYm1HDdK+97QwBzN2bSfpYfD/9giK+sJbSbuIIaYKDsM46WNPD51gCdzkjjUvGRQy6W3VJtYoUDK3bilbKnI1FhNWYFvfva3RfQS+B/ZIQCNwaRZ1YSzw0c9kMf1IDBMm1ozH7JHipDkdn9xmfn45x+ckyrZhU8xo6CFLNleSKC9LoEJxzEnIQwiWVYCBwNipQwhwZ/tRYA== Received: from VI1PR03MB2973.eurprd03.prod.outlook.com (2603:10a6:802:2e::18) by DU2PR03MB10046.eurprd03.prod.outlook.com (2603:10a6:10:492::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7409.55; Mon, 15 Apr 2024 14:19:02 +0000 Received: from VI1PR03MB2973.eurprd03.prod.outlook.com ([fe80::af5c:6eb0:6da0:f456]) by VI1PR03MB2973.eurprd03.prod.outlook.com ([fe80::af5c:6eb0:6da0:f456%7]) with mapi id 15.20.7409.053; Mon, 15 Apr 2024 14:19:01 +0000 From: =?iso-8859-2?Q?Marek_Anio=B3a?= To: Martin Simmons CC: "freebsd-security@freebsd.org" Subject: Re: cpu-microcode-intel-20231114 Thread-Topic: cpu-microcode-intel-20231114 Thread-Index: AQHajxP9aENurjjlX0GCLDoKQdTAiLFpWzYpgAADh7A= Date: Mon, 15 Apr 2024 14:19:01 +0000 Message-ID: References: <202404151356.43FDu3d7023044@higson.cam.lispworks.com> In-Reply-To: <202404151356.43FDu3d7023044@higson.cam.lispworks.com> Accept-Language: en-US, pl-PL Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: x-ms-exchange-messagesentrepresentingtype: 1 x-tmn: [VmPszM/pFm+X1FF585W8JVR40kA6lZKz] x-ms-publictraffictype: Email x-ms-traffictypediagnostic: VI1PR03MB2973:EE_|DU2PR03MB10046:EE_ x-ms-office365-filtering-correlation-id: 52390b7b-4840-4ed8-5213-08dc5d56ffaf x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: yAZGHicFBUNgZ0Lxjh13SM8dtf/8T5jIxKdisTiFOAl/3f2q6MCIminjkAos7Rh0R2UVjRRlF0HIDKFjGUfwtfq1DXq7eWETSR2HlK9q3D8fjbYCvqXIdZw5dof38QNW5FoRm4lxczRc7KIpyuZAWrwCm/mwNlNtWm3nh4Sw9FI/26ajQUi63G6Dq1j46+r6g293HEpcvosUcMgC0V8KD8oJhqcpGj4Jfkzuw5sJafV1CAj0gPvPDKvIpNoxrnGE74vct3GduK4DNYxpjjbv62tUFhbKpKyCN76QF72WUsI0vvkX8k/7DOb1RdG93n9lzcl2093j9QGyrP48HBnXa7v47zYj0nQshuc3jKEb/WhG9gf4i/uK9dOz5SZUk1FW54fTZKmwPQmKbJqDlmNRQtHHo7SV447GMHSnyl9NyGbu2eWRc8Jpq5gEuCeLnul33UP8MIUBXpWvokl6hvIgwGhoiuNdXLmzvYJfepze3A79QB0F4GFQvsyr+usJemC/2QAJ7LvJghBMIVUQpuEwaKWUwUAjst0ekAdKt5FgG/Wuq32rLy72YwUOefgiwZ0IGayr0mzq/tiiqygEGNTHwoTdyBkfedvUXkDfnX9yfGelzoIVzI9U/0bDnt5zau9JuC4WDxwkB/F8/pyYFcibLok3nySTfx0zr1MxUVzZ1As= x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-2?Q?/qwje1EwiiSsqyhklPMRbyK5H6M9w/+By5HCH39jr4oTJFj4PIZ02NMpCw?= =?iso-8859-2?Q?qnpI+OqvX/o8LQFtKX2xQjtCuI957iZGq9MCaG4wBg3d1vDBJFn/c3cWh2?= =?iso-8859-2?Q?5HWwjQkID8CXYo0r317eYcgY0OnvCmb+yW77qorKNad0dVei9piu6SbBhy?= =?iso-8859-2?Q?TUUXg6tbT0wJE4vVpyJ1kI1ZgZusK8cG189bTAmwwG+h9f1UypEBYNQDqa?= =?iso-8859-2?Q?fuKal3GcfJoS+44kvxCZvQUzPBtNJq903TVF1mSy6Q27uAIcZr0ajf2nly?= =?iso-8859-2?Q?mawdVKtViJ3kjgxN+MvBQgHIc4V4cEdfFq5jjGt0L0z9ygLLBuCXh7GN8B?= =?iso-8859-2?Q?hU3WYCKPLtxdBJT5LVsbY/ttOfCy3cYro/zDbEdkeii96LyfXe90ALDN8w?= =?iso-8859-2?Q?echFu1TRJo/03hkPn7h49OfEhyvreIzhBOf5ZnTs6E2ezalk4XYYJb89jN?= =?iso-8859-2?Q?W+1GVniog6mg2La6tB+FI+JFpgCTf0sKIueDcJ1Z41MmPIdgTxrBC52MsB?= =?iso-8859-2?Q?LtYWKeh8fuG9hZ31Mew4dLLReQfRmJJIFPv8kwJKEjHrYT+VEZAHkDyClm?= =?iso-8859-2?Q?vAaf+XiHYkNKJKQ7SsD/ulbRjxfF5OxaHSsvVRjXhO6ieQ8J6PbPlhvGyI?= =?iso-8859-2?Q?z8B7K08H5Un3fUQ2p06GwLNWxaw88kVElJiXbOCm9oFpv5xHyw1orFTgTl?= =?iso-8859-2?Q?yWq1CCeDfVnMLOzGONVbOoRHQ5u1WGq6O82nBc7QdYBA31QJJM0yzFaRQ+?= =?iso-8859-2?Q?QiWaZ9f+cxmro/0S4uVo8SCbjQjbpsvF6KDWxQurjFUEs+ANBLwr004ghU?= =?iso-8859-2?Q?/6u/kdz8KXel+JnTipiytJHTg9+fC3/iv/gqkfUMMTu6RFnTkS76ovkUvh?= =?iso-8859-2?Q?PCU2Oo6fnu+IkyH6bA8pLeIk7ye1a+kg0Eb0bCRHsPBib8ZGIxWe/7ErV8?= =?iso-8859-2?Q?iED5b5alLMy7XWKEOJrTHzUgx5nXR8G/+BRUR2M3ti2231dPRKOs3ABr4P?= =?iso-8859-2?Q?9bS/WjrFULJa5S10ceW9TrKP9pzI4s2xpPlWCVcukdioFiLVQPmrFUOoDo?= =?iso-8859-2?Q?xIiRo/o2dtTOw5sv5uphYqaIDk1bZMy4iRgxcguQW1NVIKEkmkdnp3ZMcc?= =?iso-8859-2?Q?YaOGRUwmPCdY+VOIeNE/gN3qkPuGmfZeTJxcU7BTJvUXGLRKNHNXnwmIOt?= =?iso-8859-2?Q?/lTGwldYWzyOJhd0WidNBB3CgcFd5Of4ZDyCnj/JfuYLYOH156wFt4AbhQ?= =?iso-8859-2?Q?Ajyj14j9ursgNR+HOGvkQxvm6JsSAyejLu+8mRKjY=3D?= Content-Type: text/plain; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 X-OriginatorOrg: outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: VI1PR03MB2973.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-Network-Message-Id: 52390b7b-4840-4ed8-5213-08dc5d56ffaf X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Apr 2024 14:19:01.7571 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU2PR03MB10046 X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:8075, ipnet:40.80.0.0/12, country:US] X-Rspamd-Queue-Id: 4VJ8Rs0C83z4cfZ No, it only shows the old version:=0A= =0A= =A0 ~ # pkg search cpu-microcode-intel=0A= =A0 cpu-microcode-intel-20231114 =A0 Intel CPU microcode updates=0A= =A0 ~ #=0A= =0A= The latest version (20240312) is not available.=0A= =0A= =0A= =0A= From:=A0Martin Simmons =0A= Sent:=A0Monday, April 15, 2024 15:56=0A= To:=A0Marek Anio=B3a =0A= Cc:=A0freebsd-security@freebsd.org =0A= Subject:=A0Re: cpu-microcode-intel-20231114=0A= =A0=0A= >>>>> On Mon, 15 Apr 2024 09:09:57 +0000, =3D?iso-8859-2?Q?Marek Anio=3DB3a= ?=3D said:=0A= >=0A= > As of 13 March 2024. "pkg audit" reports the following vulnerabilities in= FreeBSD 13.3-RELEASE-p1:=0A= >=0A= > cpu-microcode-intel-20231114 is vulnerable:=0A= > =A0 Intel processors - multiple vulnerabilities=0A= > =A0 CVE: CVE-2023-43490=0A= > =A0 CVE: CVE-2023-22655=0A= > =A0 CVE: CVE-2023-28746=0A= > =A0 CVE: CVE-2023-38575=0A= > =A0 CVE: CVE-2023-39368=0A= > =A0 WWW: https://vuxml.FreeBSD.org/freebsd/b6dd9d93-e09b-11ee-92fc-1c697a= 616631.html=0A= >=0A= > Found 1 issue(s) in 1 installed package(s).=0A= >=0A= > The website https://www.freshports.org/sysutils/cpu-microcode-intel/=A0sh= ows that an update to the package appeared the day before (2024-03-12), but= the BINARY package providing THE UPDATE IS STILL NOT AVAILABLE!=0A= >=0A= > Should this be the case?=0A= > Or, should I update the microcode in some other way?=0A= =0A= pkg search cpu-microcode-intel says the latest version is called=0A= cpu-microcode-intel-20240312.=A0 I don't know why these packages have dates= in=0A= their names so they don't upgrade automatically.=