Re: [gentoo-user] Kudos on prompt release of gentoo-sources w/ Zenbleed mitigation

2023-07-25 Thread Peter Böhm
Am Dienstag, 25. Juli 2023, 20:48:23 CEST schrieb Matt Connell:

> Not that I doubt you but is there a link for the specific for the fix?
>
> I'm interested in what the mitigation was and also for "Gentoo being
> awesome" propaganda purposes.

Patch:

https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?
h=linux-6.1.y=ed9b87010aa84c157096f98c322491e9af8e8f07

https://www.phoronix.com/news/Linux-Mitigate-Zenbleed
=>
https://lock.cmpxchg8b.com/zenbleed.html

Regards,
Peter







Re: [gentoo-user] Kudos on prompt release of gentoo-sources w/ Zenbleed mitigation

2023-07-25 Thread Matt Connell
On Tue, 2023-07-25 at 15:19 +, Grant Edwards wrote:
> Thanks and well done to the Gentoo Kernel Project for promptly pushing
> out 5.15.122, 6.1.41, et alia. Those latest kernels add mitigation for
> the "Zenbleed" vulnerability found in AMD Ryzen and Epyc processors.

Not that I doubt you but is there a link for the specific for the fix?

I'm interested in what the mitigation was and also for "Gentoo being
awesome" propaganda purposes.



[gentoo-user] Re: Kudos on prompt release of gentoo-sources w/ Zenbleed mitigation

2023-07-25 Thread Grant Edwards
On 2023-07-25, Grant Edwards  wrote:
> Thanks and well done to the Gentoo Kernel Project for promptly pushing
> out 5.15.122, 6.1.41, et alia. Those latest kernels add mitigation for
> the "Zenbleed" vulnerability found in AMD Ryzen and Epyc processors.

FWIW, Zenbleed affects only "Zen2" family parts:

https://gadgetversus.com/processor/amd-zen-2-processors-list/
https://en.wikipedia.org/wiki/Zen_2

--
Grant





[gentoo-user] Kudos on prompt release of gentoo-sources w/ Zenbleed mitigation

2023-07-25 Thread Grant Edwards
Thanks and well done to the Gentoo Kernel Project for promptly pushing
out 5.15.122, 6.1.41, et alia. Those latest kernels add mitigation for
the "Zenbleed" vulnerability found in AMD Ryzen and Epyc processors.

https://www.theregister.com/2023/07/24/amd_zenbleed_bug/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20593
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7008.html

I noticed that my Ubunutu server machines got a kernel update this
morning also, and I assumed that update also contained the Zenbleed
mitigation -- but it did not. Ubuntu apparently has not pushed out
kernel updates for that yet. [My Ubuntu machines are unaffected, but
I'd be a little worried if they were.]