零刻 Ser5 MAX (5800H) 更新 CPU 微码缓解漏洞

更新 CPU 微码

该迷你主机可以保持 54W 功率长时间工作不降频,且突发功率也不会超过 54W。这个特性比较适合装 PVE 等系统做服务器。在这种情况下,默认微码版本(0x0a50000d)包含未修复的 CPU 漏洞,虚拟机场景对安全性影响较大,且暂时无法通过安装各个发行版提供的包来更新,所以可以尝试进行手动修复。

构建及应用微码方式

参考:https://github.com/divestedcg/real-ucode

微码构建 OS:Fedora 39

  • git clone https://github.com/divestedcg/real-ucode.git --depth 1

  • cd real-ucode

  • git clone https://github.com/platomav/CPUMicrocodes.git --depth 1

  • git clone https://github.com/AndyLavr/amd-ucodegen.git --depth 1

  • cd amd-ucodegen

  • git apply ../amd-ucodegen-tweak.diff

  • make

  • cd ../CPUMicrocodes

  • mv ../amd-ucodegen/amd-ucodegen .

  • source ../process-amd.sh

  • source ../process-intel.sh

  • ./amd-ucodegen -o microcode_amd_fam19h.bin AMD/cpu00A50F00_ver0A50000F_2023-07-07_72B4B8C6.bin

  • 将当前目录的“microcode_amd_fam19h.bin”文件放到“/lib/firmware/amd-ucode”目录,替换掉原来的“/lib/firmware/amd-ucode/microcode_amd_fam19h.bin”文件(记得备份原来的文件)。

    • 其中 19h 为 CPU family,需要根据 CPU 实际情况替换。

  • dracut --regenerate-all --force

构建时,若出现相关命令不存在的提示,根据提示安装对应包即可。

在 PVE 系统中更新微码

通过上面方法构建出来的微码也可以用在 PVE 系统上,只需要将构建出来的“microcode_amd_fam19h.bin”文件也放置于“/lib/firmware/amd-ucode”目录替换掉(记得备份)原来的文件,然后执行 update-initramfs -u,重启即可生效。

如果手动构建对你来说不方便,可以使用我构建好的,仅限 5800H。

重启后,运行 dmesg | grep microcode,输出中看到类似“microcode: CPU0: new patch_level=0x0a50000f”字样即为成功。


一些其他的笔记(与主要内容无关)

构建出来的文件比发行版提供的小不少。可能是因为发行版提供的包含所有 fam19h(Family 25)CPU 的微码,自己构建就只包含这一个特定 CPU 的。

可以从下面的链接中检查最新的微码版本(先用 lscpu 命令获取信息)

https://gitlab.com/kernel-firmware/linux-firmware/-/tree/main/amd-ucode

CPU

信息

文件

AMD 4800U/4700U

Family=0x17 Model=0x60 Stepping=0x01

‎AMD/cpu00860F01

AMD 5800H


AMD/cpu00A50F00

Intel N95


Intel/cpuB06E0