5 ms·
There are microcode updates for this already https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3034.html https://www.amd.com/en/resources/produc
by eggnet 5mo ago
There are microcode updates for this already https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3034.html https://www.amd.com/en/resources/product-security/bulletin/a...
- negura 5mo agobut is it possible to verify that the cloud provider has applied the update?
- nvme0n1p1 5mo ago/proc/cpuinfo shows the current microcode version
- negura 5mo agoi don't think the information that unprivilleged VMs can obtain from that is necessarily reliable. for example with Xen as hypervisor only dom0 is privilleged (as management console for the system) and still it needs to call dedicated tooling in order to read or manage CPU features like clock speed or frequency scaling
- edelbitter 5mo ago/proc/cpuinfo shows whatever the hypervisor said, often simply "microcode : 0x1000065" https://github.com/torvalds/linux/commit/518e7b94817abed94becfe6a44f1ece0d4745afe https://github.com/torvalds/linux/commit/518e7b94817abed94be... https://github.com/qemu/qemu/blob/ac6721b88df944ade0048822b2b74210f543d656/target/i386/cpu.c#L10179-L10190 https://github.com/qemu/qemu/blob/ac6721b88df944ade0048822b2...
- eggnet 5mo agoYes, it is. You do have to have some infrastructure you trust somewhere to validate an attestation report from the confidential VM.
- wmf 5mo agoThe SEV-SNP attestation includes the microcode version. https://www.amd.com/content/dam/amd/en/documents/developer/lss-snp-attestation.pdf https://www.amd.com/content/dam/amd/en/documents/developer/l...