From nobody Mon Apr 15 09:09:57 2024 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4VJ1bG4fxJz5FfXj for ; Mon, 15 Apr 2024 09:10:02 +0000 (UTC) (envelope-from man130117@outlook.com) Received: from EUR05-DB8-obe.outbound.protection.outlook.com (mail-db8eur05olkn20810.outbound.protection.outlook.com [IPv6:2a01:111:f400:7e1a::810]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.protection.outlook.com", Issuer "DigiCert Cloud Services CA-1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4VJ1bF4Zrgz4v67 for ; Mon, 15 Apr 2024 09:10:01 +0000 (UTC) (envelope-from man130117@outlook.com) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=outlook.com header.s=selector1 header.b=Un3Wq2oz; dmarc=pass (policy=none) header.from=outlook.com; spf=pass (mx1.freebsd.org: domain of man130117@outlook.com designates 2a01:111:f400:7e1a::810 as permitted sender) smtp.mailfrom=man130117@outlook.com; arc=pass ("microsoft.com:s=arcselector9901:i=1") ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=am+QDqCMD+A3ZlJJE5GFV2OIFUt3tfpIdhnupQyksBiZMgOwAtShJWR45uS0hh/Dv90AwLVzUrg6C12KUxConDpT+YkV4k2c+2XISAYX2k+Np1evy+DxSimnwOSSJJ3AYInCejDY47W/STX8WD+YLvpSIx1NoqF7mwh7cgc0bv9ueFpnjvpWfGarXDsq47NbwReFgfizwMG7+wBNlzcM0J2DO52u4dHWMF5NolOK+pjky58XCMg3DTGpBWkJd1pBDpB+ADKZKTc9O6UV3BomqVHlb5JCzr+8q6I611cIKBByEbcBDvr+LX09jYSiqjhXR6TRYmSrIRR0ZLlAA2d92g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=R83NuO2YN68sE21M4stg1g/kSBxW0HDclXPanj2+88w=; b=U6SdrWgWdapxy0FINp0CDPNhgHyPYj7UWRuEwvK5Iwmp+tfeYlFvlRvwTK1g51mL7eUKdHEk7wdllVwzbrzwp8XdOm51dHVEDgRIdY7Atj/o9GVodm8LwLzVUHpPLqf7k+VpdvySFBthMUwIzOz+49pHonZZaJDHxteF4JTnFuBGfNjMLFYldlnTzuuRs5c936WBKwdfFhKQolweIzprLIRDX8SNzDHPL07rvSUcAQm9ETa8tJzT7ckafFSxxIcP8K3DJnH+viLOllPs0rBxhF5cR7ZLx73QcG1uISTEqa3bhvRn8SqL6Te/JKxEvMnRioG/cRcgbpIS5wnZCumnug== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=outlook.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=R83NuO2YN68sE21M4stg1g/kSBxW0HDclXPanj2+88w=; b=Un3Wq2ozSIEqVUrBtMGhFRbMdfRHdaJgots8fgrhYIF5omKeZMX3690SPrHIcVslOeDXGV+8bEOGdr8vGPzFTxv7rY1KC40sK5Bn58hnP9D5jVI4H7WDvP/kMGhsJFvWj7lUv00I6mPzFwfADR7DvlZdTNLNzgqA88syaSP4z0HpCPyumi0KN2ICASAZTYFEcWsXcVrufQ9mJejOoIvoRkOThpGESlP+eydYIJ1KzyXR88q27Hr3CjPRal3uMFXsBMIhcIfNXgXx7/1g3nHZKgV6XDlkBlVQkQUX6rIPg1K/le2b8YUB5+d27roWIuNqG5dGOYt+d9bHdFqbOh6QIw== Received: from AM5PR03MB2962.eurprd03.prod.outlook.com (2603:10a6:206:19::17) by VI0PR03MB10282.eurprd03.prod.outlook.com (2603:10a6:800:20d::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7409.55; Mon, 15 Apr 2024 09:09:57 +0000 Received: from AM5PR03MB2962.eurprd03.prod.outlook.com ([fe80::2088:14e0:30a2:9d0c]) by AM5PR03MB2962.eurprd03.prod.outlook.com ([fe80::2088:14e0:30a2:9d0c%3]) with mapi id 15.20.7409.042; Mon, 15 Apr 2024 09:09:57 +0000 From: =?iso-8859-2?Q?Marek_Anio=B3a?= To: "freebsd-security@freebsd.org" Subject: cpu-microcode-intel-20231114 Thread-Topic: cpu-microcode-intel-20231114 Thread-Index: AQHajxP9aENurjjlX0GCLDoKQdTAiA== Date: Mon, 15 Apr 2024 09:09:57 +0000 Message-ID: Accept-Language: en-US, pl-PL Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: x-ms-exchange-messagesentrepresentingtype: 1 x-tmn: [AItPaj9Otu8b35IuTRcSRq//flKPzh/k] x-ms-publictraffictype: Email x-ms-traffictypediagnostic: AM5PR03MB2962:EE_|VI0PR03MB10282:EE_ x-ms-office365-filtering-correlation-id: 6ca7dd97-c908-43ee-f5d0-08dc5d2bd29f x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: O5PwY5OLslzHIVYmcMEm0hGGVNhst3sF6VHkB4RR8KDSfflYEXiDH5wx+eXfoH11SnBxujS4Gb6Z/8+UrYR/lFXgl+mu+uSKfVajuWSzxpz+JfuxEerPDb5A+/cv5s+kzLFYAM6wPfmUcINrWkNUuIRacX7rkf9fcv2Yo5Axfj0bzMEh0N2Vh5SbLO/LXhitJ7grP7w7xQrtrSAo+ELwTNJZ8XsoZFoMLv03u3/mN2gBXgkyz8LhThTWkVqAOqaWeIzVKfAWVVgHyHSB2abZV72GtQ5QpUdeBEviZSbYqQKwR04ge94XKZhhpHhi48Tr0rtU7yXBLd2b+ZGFueyO8vNq3/n5vgVt6cV0IeZR+tF019UrlORmRgQMjcjEz0viK+92qlVw/gnpJvLY4xuHbM7+gZ9w6cUVRQgvSVDv5fdG62PewC3HKyOgLTy7/Rkhnc6NoVqLIDjjM+wkmyhrCWyUOxTv1/v4kf6zFhn8iuVGHl1nOX6H4DTPQlHp4R2X5Km6mqeM/lAXouN4X6/A79zzbYz06qLKt9hlUci3cEolHu6U5uCCh1569EYueXQmRR81nwXPtA+xgw+w60Az5XldsufZuN1mMTisdfYu00tW4QLSDOswDGABvZDo0L2gW3e/wCgH+ap+acc+eXNb6eyQB28nl/FLle6SlKvfMCY= x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-2?Q?WkdcCyfc2m3ec8Ldjj5RhO+juj8NOja6OGeO2/+J255feuflRxseaDRlxn?= =?iso-8859-2?Q?WXlp3alhIRUpjJKRDSnhIY5elKxkoHqf8aRQqPeugpNhEbTKo/eWzHrmFY?= =?iso-8859-2?Q?utMIv3RBzPYYs1cajhQ8C4s/8mN6EEzNirWx/+V1sw0OUhJ1vqljin89LY?= =?iso-8859-2?Q?GBx6GPAvJlHXHn8lPHCTdri6iyxG/k10YDTtaGODeY0QoA7HSc3RzgEl1N?= =?iso-8859-2?Q?Mp953c7t/ZdynjkAd9XPXj9I1YRin799bVeVqmlPmYUMkwPB8B/WcKjSbR?= =?iso-8859-2?Q?An7c7gsMxATwMYxKvFRzJjqnsaBtQ392qciZjTfasNQOapH2dczZUDJRM4?= =?iso-8859-2?Q?InzqUcvekeehEeLj1i0NqTlQK43MNi3VXjoScniKxigK30ZjFnh+TVtrIn?= =?iso-8859-2?Q?Miib8a/cDWcDli2DPAd1SjrpZjeO1vhgQqR5vMfw/psP1L6ZUJcickDqix?= =?iso-8859-2?Q?UwALxy8kLNUQMgNW64yXbi4QoIk3NRaH0uLcX7naP7AKCO8TTDE8xvYx7r?= =?iso-8859-2?Q?+x97Jg+F7BjnG0nftzP0HJHH+077ApPWuhXbTbHPxV0dhgFk8r+QNwRcO8?= =?iso-8859-2?Q?RasesBJvow0TG5dDEZGhF7CqkiDcFG+cHIQmsQP4JlcIStUmgq3XYSUh3b?= =?iso-8859-2?Q?kKyat9/M5+uVbNuYFXMFIHIs+cKrrCKlVd7qpHB9kMpCpYX4sOlFZnNaCo?= =?iso-8859-2?Q?rEbGJG0lLDOYbR8iZHESGnfh8uFvzJz32UpU20TzwOOwuwJl2+5ZKOiTZj?= =?iso-8859-2?Q?zy84cg0wo5TUeU+5fSc6VEwI2Ejt6j898oD8YxRKenHS4r7+liwWAVUPN1?= =?iso-8859-2?Q?rJ/TpyI5dpUOJwsnffY2SMtZWdkHbtPTyc71F6D9538EQDmvZonsle/IoC?= =?iso-8859-2?Q?GyPIUbebHTle0vysnRncDKRkPHuPJK1AD98PKDHTCDA/F5rjxqEFhhWYqw?= =?iso-8859-2?Q?E1MbdE7gxxsqhTUijr0zDz3+VZAhz8yx9Eijq79vgOUVbxkXpSg9ULPNoS?= =?iso-8859-2?Q?jYMhzFqCYu0EVYN1e39wiCv7v3J72AD7FjS6+CT5vIRQ/bAL6fUBEHdwn0?= =?iso-8859-2?Q?mz0cQfKYjxPlZTln9g9EHqxKnLR0Zw1g4+bkDZlORxg9679s+VWYYbETaH?= =?iso-8859-2?Q?6aYVLaki7p9l1BPJAG85v8XfX84UfoZubT5PH5btcwVODFwg+CyDRzvoT/?= =?iso-8859-2?Q?6cZYSP759I3HNIFRfP2BKYsOXGnqrAZIkSviuFHh9jiG5psAG7FyeRZMBc?= =?iso-8859-2?Q?nA2ySjT/PgWklN9fmtZTG4/Zu+edUPNUckDL1ULos=3D?= Content-Type: text/plain; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 X-OriginatorOrg: outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: AM5PR03MB2962.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-Network-Message-Id: 6ca7dd97-c908-43ee-f5d0-08dc5d2bd29f X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Apr 2024 09:09:57.8185 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI0PR03MB10282 X-Spamd-Bar: ---- X-Spamd-Result: default: False [-4.12 / 15.00]; ARC_ALLOW(-1.00)[microsoft.com:s=arcselector9901:i=1]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.83)[-0.831]; R_MIXED_CHARSET(0.71)[subject]; DMARC_POLICY_ALLOW(-0.50)[outlook.com,none]; R_DKIM_ALLOW(-0.20)[outlook.com:s=selector1]; R_SPF_ALLOW(-0.20)[+ip6:2a01:111:f400::/48]; MIME_GOOD(-0.10)[text/plain]; DWL_DNSWL_NONE(0.00)[outlook.com:dkim]; RCPT_COUNT_ONE(0.00)[1]; FREEMAIL_FROM(0.00)[outlook.com]; ASN(0.00)[asn:8075, ipnet:2a01:111:f000::/36, country:US]; FREEMAIL_ENVFROM(0.00)[outlook.com]; MISSING_XM_UA(0.00)[]; MIME_TRACE(0.00)[0:+]; FROM_EQ_ENVFROM(0.00)[]; MLMMJ_DEST(0.00)[freebsd-security@freebsd.org]; TO_DN_EQ_ADDR_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MID_RHS_MATCH_FROMTLD(0.00)[]; RCVD_TLS_LAST(0.00)[]; DKIM_TRACE(0.00)[outlook.com:+] X-Rspamd-Queue-Id: 4VJ1bF4Zrgz4v67 As of 13 March 2024. "pkg audit" reports the following vulnerabilities in F= reeBSD 13.3-RELEASE-p1:=0A= =0A= cpu-microcode-intel-20231114 is vulnerable:=0A= =A0 Intel processors - multiple vulnerabilities=0A= =A0 CVE: CVE-2023-43490=0A= =A0 CVE: CVE-2023-22655=0A= =A0 CVE: CVE-2023-28746=0A= =A0 CVE: CVE-2023-38575=0A= =A0 CVE: CVE-2023-39368=0A= =A0 WWW: https://vuxml.FreeBSD.org/freebsd/b6dd9d93-e09b-11ee-92fc-1c697a61= 6631.html=0A= =0A= Found 1 issue(s) in 1 installed package(s).=0A= =0A= The website https://www.freshports.org/sysutils/cpu-microcode-intel/ shows = that an update to the package appeared the day before (2024-03-12), but the= BINARY package providing THE UPDATE IS STILL NOT AVAILABLE!=0A= =0A= Should this be the case?=0A= Or, should I update the microcode in some other way?=0A= =0A= Marek Anio=B3a=0A=