Unsolved
This post is more than 5 years old
1 Rookie
•
38 Posts
1
2779
Intel BUG - speculative execution side-channel vulnerabilities
Ok Dell - the cat is out of the bag now and the managers that see the news will start harassing IT staff for a plan. Where do we go for guidance on your release schedule for the CPU microcode updates?
theflash1932
7 Technologist
7 Technologist
•
16.3K Posts
0
January 4th, 2018 13:00
Intel has to finish and release them (possibly next week, I heard) before they will be available for Dell to integrate and package as BIOS updates. There is also a possibility that old machines won't even get BIOS updates to address it (those well outside of the support lifecycle - 9G and 10G and older, at least).
Here is where you should go for "guidance":
http://www.dell.com/support/article/us/en/04/sln308588/microprocessor-side-channel-attacks--cve-2017-5715--cve-2017-5753--cve-2017-5754---impact-on-dell-emc-products--dell-enterprise-servers--storage-and-networking-?lang=en
pseud0
22 Posts
0
January 4th, 2018 13:00
This is a curious position for Dell to be in given that there is evidence that they've been preparing for this for some time, here is one they have released. Yes, I know it is a desktop platform in a rack but their statement on client platforms is similar
http://www.dell.com/support/home/uk/en/ukbsdt1/drivers/driversdetails?driverId=MXXTN
pseud0
22 Posts
0
January 4th, 2018 14:00
This may be part of the reason that hardware vendors don't have all the information ready
http://xenbits.xen.org/xsa/advisory-254.html
"This vulnerability was originally scheduled to be made public on 9
January. It was accelerated at the request of the discloser due to
one of the issues being made public."
theflash1932
7 Technologist
7 Technologist
•
16.3K Posts
0
January 4th, 2018 14:00
May just back up what Intel said that they have been working on it for some time and were poised to announce it as soon as the fix was ready ... different platforms/technology may be affected differently and/or require different levels of fixes.
Just saw your post, along the same lines ...