DaemonForums  

Go Back   DaemonForums > OpenBSD > OpenBSD General

OpenBSD General Other questions regarding OpenBSD which do not fit in any of the categories below.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 12th September 2015
Monti Monti is offline
Port Guard
 
Join Date: Apr 2015
Location: In'Da House
Posts: 10
Default CPU's and hardware vulnerabilities

Hi,

I have read this article which talks about bugs in the hardware architecture of Intel Core 2 Duo processors.

I am wondering if anyone have some thoughts or knowledge when it comes to other cpu's? Both Intel and AMD that is.


Thanks
Reply With Quote
  #2   (View Single Post)  
Old 12th September 2015
e1-531g e1-531g is offline
ISO Quartermaster
 
Join Date: Mar 2014
Posts: 628
Default

For Intel's CPUs search for "Specification Update" pdfs or something like that.

Example: https://www-ssl.intel.com/content/da...pec-update.pdf

As far as I know there are two ways for microcode to be applied. First is with new version of BIOS/UEFI. Second is update by OS, for example in Debian there is microcode in non-free section of official repo:
https://packages.debian.org/jessie/intel-microcode
You should also know that not every bug in hardware can be fixed by microcode update.
Reply With Quote
  #3   (View Single Post)  
Old 12th September 2015
Monti Monti is offline
Port Guard
 
Join Date: Apr 2015
Location: In'Da House
Posts: 10
Default

Thanks a lot for your info and links e1. This is interesting.

Since the intel-microcode update link is for Debian, and if I understand this correctly, would it be possible to just use a Debian live dvd and do the microcode update for those of us using OpenBSD?

I am also trying to get an overview or a picture of the tendency for these bugs to occur with the different cpu models with both Intel and AMD. So if this is possible more input is appreciated.

Thanks
Reply With Quote
  #4   (View Single Post)  
Old 12th September 2015
IdOp's Avatar
IdOp IdOp is offline
Too dumb for a smartphone
 
Join Date: May 2008
Location: twisting on the daemon's fork(2)
Posts: 1,027
Default

I don't know about vulnerabilities specifically, but here's an example with

AMD CPU errata

The errata section is very long, going from page 13 to 99.

I was once alerted to an AMD CPU erratum by a line in an OpenBSD dmesg which said

Code:
cpu0: AMD erratum 89 present, BIOS upgrade may be required
Searching for that led to a document similar to the one linked above.

My sense is that CPU errata are very common and always have been.
Reply With Quote
  #5   (View Single Post)  
Old 12th September 2015
e1-531g e1-531g is offline
ISO Quartermaster
 
Join Date: Mar 2014
Posts: 628
Default

You can also read article from heise online called "Processor Whispers: About Bugs, Bidders and Batmen" by Andreas Stiller
https://web.archive.org/web/20131207...n-1775150.html

Last edited by e1-531g; 12th September 2015 at 09:37 PM.
Reply With Quote
  #6   (View Single Post)  
Old 12th September 2015
Monti Monti is offline
Port Guard
 
Join Date: Apr 2015
Location: In'Da House
Posts: 10
Default

Thank you very much IdOp for useful info. And thank you e1 for the additional link. Both giving me the perspectives I was searching for. Really appreciate it.

Monti
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
tracking vulnerabilities albator NetBSD Security 4 22nd September 2011 07:33 PM
Vulnerabilities in STARTTLS implementations J65nko News 0 8th March 2011 12:50 PM
OpenSSL updates fix vulnerabilities J65nko News 0 4th June 2010 12:48 PM
ClamAV 0.96.1 fixes DoS vulnerabilities J65nko News 0 25th May 2010 08:41 PM
Hardware recommendation: what hardware to buy for my new FreeBSD desktop? Broodjegehaktmetmayo General Hardware 92 11th February 2009 10:43 PM


All times are GMT. The time now is 08:46 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick