On 20.10.2025 15:19, Andrew Cooper wrote: > For Zen3-5 microcode blobs signed with the updated signature scheme, the > checksum field has been reused to be a min_revision field, referring to the > microcode revision which fixed Entrysign (SB-7033, CVE-2024-36347). > > Cross-check this when trying to load microcode, but allow --force to override > it. If the signature scheme is genuinely different, a #GP will occur. > > Signed-off-by: Andrew Cooper <[email protected]>
Acked-by: Jan Beulich <[email protected]> Might be upgradable to R-b if only I knew where - if anywhere - this is documented. I can't spot anything in PM vol 2 in particular. Jan
