Downfall (CVE-2022-40982) — 202?

Has the Downfall microcode update not been released with 202?

image

Any way I can check or run that manually, or is it the kernel that has not been updated?

(No other issues or questions about 202 :+1: )

Looking at the Intel page on this CVE, it looks like their mitigation is a fix in their microcode. We are running the latest Intel-Microcode release in IPFire.

It might be that Intel applied the microcode but did not supply any message to the kernel with regard to that fix.

It might be that your cpu is older than the Intel cutoff and so they have not applied the mitigation for your cpu or even confirmed that the cpu was affected. That has been the case with other vulnerabilities. In the past that would have resulted in a message Unaffected. That did not seem a reasonable conclusion so since a few years the kernel shows the message Vulnerable when there is no information from a cpu platform on a particular vulnerability.

The report from Intel states
Intel is not aware of any instance of any of this vulnerability being exploited outside a controlled lab environment.

Intel states
Refer to the 2022-2023 tab of the consolidated Affected Processors table: Gather Data Sampling column.

In the table that the link points to there is no 2022-2023 tab and CVE2022-40982 is not referenced in any of the tabs so it looks like Intel have removed that CVE from their current affected processors list.

EDIT:
I found the following statement in the Intel Platform Security Guidance

Processors that have met the End-of-Servicing-Lifetime (EOSL) milestone may not be listed in the following table and mitigation status of EOSL processors may not be evaluated.

that table being the affected processors table so it looks like maybe all processors affected by that CVE are no longer supported but that is a guess on m y part on the basis that the CVE is no longer listed in that affected processors table.

Thanks

FYI, I should have mentioned that, the CPU in question is Xeon E3-1245 v5 (Skylake, 4C/8T, 3.5 GHz base, with iGPU)

That cpu is marked as end of servicing lifetime so Intel will unfortunately not create any mitigations for it and will also not even check if it is affected by any new vulnerabilities.

The last servicing updates for that processor were at the end of 2019.