On Fri, Jan 12, 2018 at 3:31 PM, Chris Murphy <lists@xxxxxxxxxxxxxxxxx> wrote: > Koji contains linux-firmware-20171215-82.git2451bb22.fc27 which > contains intel-ucode from 20171117. But I don't know if this firmware > contains the microcode required to completely secure from Spectre > variant 2. Intel CPU microcode is not provided by the linux-firmware package. It is shipped in the microcode_ctl package. Did you actually find intel-ucode in linux-firmware or were you just assuming that is where it was coming from? I'm asking to make sure it was a misunderstanding because others might make the same mistake. > https://access.redhat.com/articles/3311301 > "This vulnerability requires both updated microcode and kernel patches" > > Intel has released microcode 20180108, but there are no builds in koji > yet for this version so I manually applied them from > https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File > > and also updated the initramfs with dracut -f so the change is > persistent. This does change the microcode on my laptop compared to > the Fedora supplied microcode. https://bodhi.fedoraproject.org/updates/FEDORA-2018-7e17849364 josh _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx