Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 911939 (CVE-2022-40982) - Intel DOWNFALL kernel vulnerability
Summary: Intel DOWNFALL kernel vulnerability
Status: IN_PROGRESS
Alias: CVE-2022-40982
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://downfall.page/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-09 03:15 UTC by Sam James
Modified: 2023-08-28 15:25 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-08-09 03:15:36 UTC
See https://downfall.page/.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-08-09 03:17:54 UTC
This is fixed in:
* sys-firmware/intel-microcode-20230808_p20230804
* linux-4.14.321
* linux-4.19.290
* linux-5.4.252
* linux-5.10.189
* linux-5.15.125
* linux-6.1.44
* linux-6.4.9

Note that each of these linux-* releases has a warning from Greg (https://lwn.net/Articles/940798):
>Note, PLEASE TEST this kernel if you are on the [...] tree before using it in
>a real workload. This was a quick release due to the obvious security fixes in
>it, and as such, it has not had very much testing "in the wild". Please let us
>know of any problems seen. Also note that the user/kernel api for the new
>security mitigations might be changing over time, so do not get used to them
>being fixed in stone just yet.

([...] because it's the same for each respective version, the LWN article just says 6.4.x, don't get the wrong impression).
Comment 2 Larry the Git Cow gentoo-dev 2023-08-09 03:20:53 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e1f208e1fa8c030d1bf9571b36e67d552325c73b

commit e1f208e1fa8c030d1bf9571b36e67d552325c73b
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-08-09 03:14:09 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-08-09 03:20:15 +0000

    sys-firmware/intel-microcode: stabilize 20230808_p20230804 for amd64, x86
    
    Bug: https://bugs.gentoo.org/911939
    Signed-off-by: Sam James <sam@gentoo.org>

 sys-firmware/intel-microcode/intel-microcode-20230808_p20230804.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 3 Larry the Git Cow gentoo-dev 2023-08-26 23:03:00 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1da5599076d2ea568df044227dfc9047d2cecb63

commit 1da5599076d2ea568df044227dfc9047d2cecb63
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-08-26 23:01:44 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-08-26 23:02:49 +0000

    sys-devel/gcc: add 13.2.1_p20230826
    
    Note that I plan on keywording this round of gcc snapshots shortly because
    it's: 1) a bit overdue, but 2) it contains mitigations for the performance loss
    from the recent Intel vulnerabilities.
    
    Bug: https://bugs.gentoo.org/911939
    Signed-off-by: Sam James <sam@gentoo.org>

 sys-devel/gcc/Manifest                    |  1 +
 sys-devel/gcc/gcc-13.2.1_p20230826.ebuild | 65 +++++++++++++++++++++++++++++++
 2 files changed, 66 insertions(+)
Comment 4 Larry the Git Cow gentoo-dev 2023-08-26 23:32:48 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e18f29033d1c2d1f6f2ba443e59d3349b60598a5

commit e18f29033d1c2d1f6f2ba443e59d3349b60598a5
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-08-26 23:28:08 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-08-26 23:28:43 +0000

    sys-devel/gcc: keyword 13.2.1_p20230826
    
    Bug: https://bugs.gentoo.org/911939
    Signed-off-by: Sam James <sam@gentoo.org>

 sys-devel/gcc/gcc-13.2.1_p20230826.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=28549e0b4f6c5da1319413b48d53a4b13890603a

commit 28549e0b4f6c5da1319413b48d53a4b13890603a
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-08-26 23:27:53 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-08-26 23:28:17 +0000

    sys-devel/gcc: keyword 12.3.1_p20230825
    
    Bug: https://bugs.gentoo.org/911939
    Bug: https://bugs.gentoo.org/912795
    Signed-off-by: Sam James <sam@gentoo.org>

 sys-devel/gcc/gcc-12.3.1_p20230825.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e923f99b4ad2915b0305a76e2f48cb4dc5fa2c86

commit e923f99b4ad2915b0305a76e2f48cb4dc5fa2c86
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-08-26 23:27:37 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-08-26 23:27:37 +0000

    sys-devel/gcc: keyword 11.4.1_p20230824
    
    Bug: https://bugs.gentoo.org/911939
    Signed-off-by: Sam James <sam@gentoo.org>

 sys-devel/gcc/gcc-11.4.1_p20230824.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)