intel/amd microcode updates

gwaitsi

Patron
Joined
May 18, 2020
Messages
243
I see on ubuntu linux this week alone there have been 3 intel microcode updates.

Does free/truenas even have the microcode updates loaded, and when / how are they updated to address the latest security issues?
 

mav@

iXsystems
iXsystems
Joined
Sep 29, 2011
Messages
1,428
Yes, TrueNAS 12 does update CPU microcode. Next nightly build and upcoming 12.0-U1 will include the recent Intel updates.
 

rvassar

Guru
Joined
May 2, 2018
Messages
972
As a general rule of thumb, if you're running Intel these days... Understand, this isn't a sleight against iXsystems in any way, I'm sure they're quite diligent in tracking the changes. The only sure safe fix for Spectre/Meltdown is to take the performance hit and turn off hyper-threading.
 

mav@

iXsystems
iXsystems
Joined
Sep 29, 2011
Messages
1,428
Enterprise NAS installation never had untrusted users in the system, so local vulnerabilities like this one are not a big issue typically. But we are still closely tracking reported security vulnerabilities and applying available fixes.
 

joeschmuck

Old Man
Moderator
Joined
May 28, 2011
Messages
10,996
Here you go. Read this link and it tells you how to check if your code is protected. It will provide a colorful output. Overall you will find it states there are some vulnerabilities.

And another link here basically shows you how to check this from within FreeNAS and guess what, I'm protected.
 
Top