From nobody Mon Apr 15 14:44:03 2024 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4VJ90k5z8Hz5GkGV for ; Mon, 15 Apr 2024 14:44:06 +0000 (UTC) (envelope-from man130117@outlook.com) Received: from EUR04-VI1-obe.outbound.protection.outlook.com (mail-vi1eur04olkn2085.outbound.protection.outlook.com [40.92.75.85]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.protection.outlook.com", Issuer "DigiCert Cloud Services CA-1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4VJ90k37RJz4jW5 for ; Mon, 15 Apr 2024 14:44:06 +0000 (UTC) (envelope-from man130117@outlook.com) Authentication-Results: mx1.freebsd.org; none ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=IvFvkAPZHol6qXZTL/x+h1/D6SjgdQQ825hMYeKGmx7e5cWWHcJAJr813VApam4+Hzzss9SeyW1WBkc8gdCwXQz1Etm4vY1LIHw4YrQWr9etdxm2P51JGA5AZayfpWMDxJcvxCuiWhZ7Q9+uUbPcCG40Fg8vb7QVzyOg62fhOJ1el38hGO56ctW5XcWDUZGPRgqJxmY3YXY0AiuYmoGOrIRi1jqQs9IR9avR+12zcB0tc06P9x4vCJ6Dn9JbJUTP5Rd3WWVmTOSxkgU18JQBODTSq5gFRh0DqYCUj0yFGlAf2gPKyJ52E54pp0TLeS38FjG7SU+wmrwmnRXZM4dKMA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=xRvlSvL7tnnGyZDCAo+GES1UGOJpsSwo0eXZinYPNsE=; b=B3K4aPfmjb4l1GIiny9Ll+nqhcn/ctLAM148cu+SaRDgH/LoA2VJTHLGxixgbTnXBo9tTlIlDpYMwIvsxD5ORmQwr9rTJhklPK2TMbDQXatXRJQFdJFfLFHUl6IIJ4GyR7C0760im16OYLH8XHySE/K9X/oSIE4m+AvjbTOktvNtP2pjB6I7Vq+6UI/DyQ+DoJMr+JvCZKtJyDdp1kVeQ6crYFwllzkczn3yxJOGtaa5sls0m4BVcTLb0n+I5TMwia3L24iwk+OePU8lTOt3pfPdlF4YX0y/kd0xVjA3XBHXBAizmwT7RuG5J7NDcwEKyJUC1pgg5dE90dauPpsTog== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=outlook.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=xRvlSvL7tnnGyZDCAo+GES1UGOJpsSwo0eXZinYPNsE=; b=FPxzK3sWXFgOqU9lax8IfrQwRWbhp6UfbNi2ibTgIdey0zNkPVkcKHH7hIIY3vvcNuYWSIiHptpVBQfpva51/njx6qTHZHt8iURMAZn1wptvTw0rldWDGj8J68oRoEtD2QNZ7tK7cj7ACRK0J/ZkEuqpf1L5B3kSbYLbMQOdjzWi3J4iWv/gjBEsQaLb6DrQNXiMu4a+YpJ0r1Jgpmf8CzYlrtHfXmxDO8F1E4/iMjtuP5ZIf/qCeYQPk2iq4ya/cIRXqWwS58vTobJaWOsw5ks9MCj3hnXtIkSE0yUxbf6qR/ylK709R4S1ON621U4tut7399Z6ZDooRiz/G5NgRg== Received: from VI1PR03MB2973.eurprd03.prod.outlook.com (2603:10a6:802:2e::18) by VI1PR03MB6334.eurprd03.prod.outlook.com (2603:10a6:800:138::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7409.55; Mon, 15 Apr 2024 14:44:03 +0000 Received: from VI1PR03MB2973.eurprd03.prod.outlook.com ([fe80::af5c:6eb0:6da0:f456]) by VI1PR03MB2973.eurprd03.prod.outlook.com ([fe80::af5c:6eb0:6da0:f456%7]) with mapi id 15.20.7409.053; Mon, 15 Apr 2024 14:44:03 +0000 From: =?iso-8859-2?Q?Marek_Anio=B3a?= To: infoomatic , "freebsd-security@freebsd.org" Subject: Re: cpu-microcode-intel-20231114 Thread-Topic: cpu-microcode-intel-20231114 Thread-Index: AQHajxP9aENurjjlX0GCLDoKQdTAiLFpWzYpgAADh7CAAAVGAIAAAtIw Date: Mon, 15 Apr 2024 14:44:03 +0000 Message-ID: References: <202404151356.43FDu3d7023044@higson.cam.lispworks.com> <202633d8-b51c-4f8e-8426-f42a8a79c99d@gmx.at> In-Reply-To: <202633d8-b51c-4f8e-8426-f42a8a79c99d@gmx.at> Accept-Language: en-US, pl-PL Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: x-ms-exchange-messagesentrepresentingtype: 1 x-tmn: [rhoo34CctwvHr2SvGOLo9tzSyYqWpG+k] x-ms-publictraffictype: Email x-ms-traffictypediagnostic: VI1PR03MB2973:EE_|VI1PR03MB6334:EE_ x-ms-office365-filtering-correlation-id: 8f51c596-3587-46e6-518a-08dc5d5a7e95 x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: 8eCnTCmpsTmGYgHq/td8qz/B7vKib0GOu63hE2u3QpvhD/7fkyZi5GAKtm2ih2PDz3CSBYZ+U9hGnTW1CnlgTlJmKXbYPaXtZeCNxG3T1dgZLxG3DEYOtEy0u86IqaQTmnLNWvGXzWZGxPwFvS5oHvF9pAhOuYbuWMHZXML+Xk8/5dqh5Qr9jx9ZpTQ7a01bCHDZXNeSr4wB9YJBElhPu42sFjzgmuWqEfFgePD+FIXMlb28mH0yYNP/FHaBrh4qqWxjw6yV/8+qy0/x6+suKF4TcOoy6t0Hk3w7gLD8tUYbn8WJSyaMpRz9SJ6P3hbZUkXAQY8JfGp/JMvrjmTmQt//PuCNDHWQe0e6vu5wylLau0MD1+Czbs8WJ1rnWdEdLpK2DxwWvnMt4LV7X7flQ7Hp2MXLapN3NByLe7QjMHKQXO9cUdcvFFFcYlqqfTMkvEyo0vdXq3lKie7mwhs3dJeBMpGuTjRXXGl2IH1GkY+T/gjmVr5up1OjwDJmf+/2m3MNRjBUlLqe3WfpwpBLmA/EYMHnxPPhfrYxvuxu5ZCIetrLseWGVayNd+tGW/pCmn2tkoluk6Ea+YXYZR590c0MJZXOeD9rDhxHV7WTL8qLSumtYr5aP1ASyFv3EaJvgqRosLqksSBjv85cG8pRmrtRbIM5CFqCUlphmqIW+bQ= x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-2?Q?GO4mYlmBgpWLXiGtQSUdBI9bBFtXV7SoguutYFV7oZMqVbzpBgDBwRVnPW?= =?iso-8859-2?Q?GaVbFH3DDPNt2ZSv28dkhSn1WeClXJf86gynVUHMJRppgr99086aMD2SE+?= =?iso-8859-2?Q?RZY727tqy8QtiA8AhF/NkdFuB4tctRPNEcKIJgzUti7p28MpRA3CLCKKrL?= =?iso-8859-2?Q?OrN8RkpUIpGB9u8zGWpMffzAY0VUdnu6F9Kjb0cAytMdjjIqLyWrFmk+sI?= =?iso-8859-2?Q?kgqtzsSnKrQNb5qDR7o567SKmy+H5f6NZuYAY+CJbimklQGSCUJJONZe2b?= =?iso-8859-2?Q?NOgRbxEVw35koIU+2q3GfctwX9AU6aNizq2WzG/QBRlJiRXYvA+FHUv+jq?= =?iso-8859-2?Q?w26IAd5/g51ddnMwb3xWPaSGxGsaRLB6BTiUQ3jBZ7ZflKDXq3Hb0/mlIK?= =?iso-8859-2?Q?tbt0TzuDe2rwRNa/s6Xx4sGSNegs1Gt3a3ECQ1najGnM129r+hqzTHXbBQ?= =?iso-8859-2?Q?E7DxWAYQHhmBMBmSlb0NtN1HOJhkyx2cvtEdloOm52A+7bbFh5EWtQmOF8?= =?iso-8859-2?Q?t+ABi1u07ANpx39+FbeiTKkuMnBjHkBQJVtONlxk7tKphZyE303rFxaYNR?= =?iso-8859-2?Q?h1E3Qmmmbb/AvcAe39kCdjJFmNKIqn0YkbcQtQ2u7PExmHJDwjY3ORNne5?= =?iso-8859-2?Q?ldvrvgMNdLfaVteWvtr+Z9OkHiSHMJTymOODk/7nH69tZXmtakIy7aVu1z?= =?iso-8859-2?Q?2D9Yr0Vk7sK71Qt/C2/135b/GCe1FJT+5jcWAwQhR6zc/IzAba8hEJd/p5?= =?iso-8859-2?Q?Hcg9YNQEJfwySTyOtbbPCuGM/zpk9zitigmz304DWQp6ZR5QFgEmmuE7Yy?= =?iso-8859-2?Q?1qvCs8AIs8GQhkRS7ZwYGe8ob2SmUghRT7EzlpIry0DpLkH1oAjgtonGDS?= =?iso-8859-2?Q?dMvYL+QBuRFy4KKHZu1RmaWX5B3II67NLnNHVUkzn7490opULLK+VxgPcJ?= =?iso-8859-2?Q?11XNCqDa6MaZkPVCkpA47o81UGJTq1f6p8eUVqksIYFphp45xPmkuMN9S8?= =?iso-8859-2?Q?Bc9VcaVTfiVqrcXP6fR28pi56eqRhpLh32V/s+Vx4BFCHvfY/SPAzG73su?= =?iso-8859-2?Q?jrsgdZ9Jw7X82ojF7utf44LhPAwByvpEwOLmW88VpglGps9D9RREs3v/6d?= =?iso-8859-2?Q?5uy6cpC6/UY2CoAYu+oFRqPMysvA+Oq75QTY6n1XnPnBl1LF4a0qBiRle8?= =?iso-8859-2?Q?MOuhYiP8Al+MMmm+Gx1aBwkv+u1Dw+vGFrET+rOzCarksjGg+aUpMJaPwl?= =?iso-8859-2?Q?wielSLmdSk/qiBdPQGS71/c59rrw5bmOqyr83P2Oc=3D?= Content-Type: text/plain; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 X-OriginatorOrg: outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: VI1PR03MB2973.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-Network-Message-Id: 8f51c596-3587-46e6-518a-08dc5d5a7e95 X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Apr 2024 14:44:03.1298 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR03MB6334 X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:8075, ipnet:40.80.0.0/12, country:US] X-Rspamd-Queue-Id: 4VJ90k37RJz4jW5 That helped=0A= (I had "quaterly" instead of "latest" in url line of /usr/local/etc/pkg/rep= os/FreeBSD.conf).=0A= Thanks a lot=0A= =0A= =0A= From:=A0owner-freebsd-security@FreeBSD.org on behalf of infoomatic =0A= Sent:=A0Monday, April 15, 2024 16:27=0A= To:=A0freebsd-security@freebsd.org =0A= Subject:=A0Re: cpu-microcode-intel-20231114=0A= =A0=0A= pkg update -f=0A= =0A= refreshes fetches your package catalogue (latest or quarterly - see=0A= /etc/pkg/FreeBSD.conf). After that you should be able to upgrade the=0A= package.=0A= =0A= Regards,=0A= Robert=0A= =0A= =0A= On 15.04.24 16:19, Marek Anio=B3a wrote:=0A= > No, it only shows the old version:=0A= >=0A= >=A0 =A0 ~ # pkg search cpu-microcode-intel=0A= >=A0 =A0 cpu-microcode-intel-20231114 =A0 Intel CPU microcode updates=0A= >=A0 =A0 ~ #=0A= >=0A= > The latest version (20240312) is not available.=0A= >=0A= >=0A= >=0A= > From:=A0Martin Simmons =0A= > Sent:=A0Monday, April 15, 2024 15:56=0A= > To:=A0Marek Anio=B3a =0A= > Cc:=A0freebsd-security@freebsd.org =0A= > Subject:=A0Re: cpu-microcode-intel-20231114=0A= >=0A= >>>>>> On Mon, 15 Apr 2024 09:09:57 +0000, =3D?iso-8859-2?Q?Marek Anio=3DB3= a?=3D said:=0A= >>=0A= >> As of 13 March 2024. "pkg audit" reports the following vulnerabilities i= n FreeBSD 13.3-RELEASE-p1:=0A= >>=0A= >> cpu-microcode-intel-20231114 is vulnerable:=0A= >>=A0 =A0 Intel processors - multiple vulnerabilities=0A= >>=A0 =A0 CVE: CVE-2023-43490=0A= >>=A0 =A0 CVE: CVE-2023-22655=0A= >>=A0 =A0 CVE: CVE-2023-28746=0A= >>=A0 =A0 CVE: CVE-2023-38575=0A= >>=A0 =A0 CVE: CVE-2023-39368=0A= >>=A0 =A0 WWW: https://vuxml.FreeBSD.org/freebsd/b6dd9d93-e09b-11ee-92fc-1c= 697a616631.html=0A= >>=0A= >> Found 1 issue(s) in 1 installed package(s).=0A= >>=0A= >> The website https://www.freshports.org/sysutils/cpu-microcode-intel/=A0s= hows that an update to the package appeared the day before (2024-03-12), bu= t the BINARY package providing THE UPDATE IS STILL NOT AVAILABLE!=0A= >>=0A= >> Should this be the case?=0A= >> Or, should I update the microcode in some other way?=0A= >=0A= > pkg search cpu-microcode-intel says the latest version is called=0A= > cpu-microcode-intel-20240312.=A0 I don't know why these packages have dat= es in=0A= > their names so they don't upgrade automatically.=0A= =0A=