Slashdot Mirror


Intel Has a New Spectre and Meltdown Firmware Patch For You To Try Out (betanews.com)

Mark Wilson writes: The Spectre/Meltdown debacle continues to rumble on, and now the chip manufacturer has announced the availability of a new 'microcode solution' to the vulnerability. The updated firmware applies to 6th, 7th and 8th Generation Intel Core devices, and the release sees the company crossing its fingers and hoping that everything works out this time.

This is Intel's second attempt at patching the vulnerability, and this time around both the company and its customers will be praying that the fix for Skylake, Kaby Lake and Coffee Lake chips actually does the job.

4 of 130 comments (clear)

  1. Spectre only by PhrostyMcByte · · Score: 3, Informative

    You can't fix Meltdown with a CPU patch.

    1. Re:Spectre only by amorsen · · Score: 2, Informative

      It's a bit funny that this post is 5 Informative. It is exactly the wrong way around. Meltdown can be fixed with a patch. It involves speculating across a hardware security barrier, which is something that microcode has a chance to detect.

      Spectre, on the other hand, does not involve speculating into inaccessible memory. It just involves speculating into memory that the program (typically a jit compiler) is carefully avoiding touching.

      --
      Finally! A year of moderation! Ready for 2019?
  2. They've only had since June by bill_mcgonigle · · Score: 4, Informative

    Hey, Google only notified them in June and maybe they were going to get around to working on it after the holidays. And there are two new variants out this week that aren't considered, so be ready for the next round in a month or so as well.

    You can't expect Intel to get these things done immediately, people! (the class action suits are going to love that they didn't fix it with six months' warning).

    --
    My God, it's Full of Source!
    OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
  3. Re:another day another solution by Anonymous Coward · · Score: 1, Informative

    APK is a myth anyway. His sightings are about as credible as pictures of the Loch Ness monster.