Processor Vulnerability Mitigations with old Hardware

Hallo @bmmbmm01

Welcome to the IPFire community.

This message means that the processor involved has not been reviewed by Intel because it is considered too old so they have not confirmed if the processor is affected by the vulnerability or not and cannot therefore say that the mitigation that is in place will work or not, so they say that there is no mitigation.

The message used to be that the processor was Unaffected for situations where the processor had not been investigated but Intel provided a patch to the kernel code to change the message to Unknown: No mitigations.

https://community.ipfire.org/t/mmio-stale-data-vulnerability/8810
https://www.phoronix.com/news/Linux-MMIO-Stale-Data-Old-CPUs

The Linux documentation puts the statement, Unknown: No mitigations, as meaning

"The processor vulnerability status is unknown because it is out of Servicing period. Mitigation is not attempted."

In terms of all mitigations provided by any processor manufacturer, they are always implemented in IPFire in the next Core Update release after the microcode update has been released so if you are up to date with the Core Updates you will have the latest microcode updates that are available.

3 Likes