Intel and Microsoft release final Spectre Patches up to and including Sandy Bridge

Published by

Click here to post a comment for Intel and Microsoft release final Spectre Patches up to and including Sandy Bridge on our message forum
https://forums.guru3d.com/data/avatars/m/212/212547.jpg
Devla:

Asrock updated some Bioses also today. Just updated my X99 OC Formula and it now passes Inspectre.
Gigabyte also released new bioses for all(?) its Z270 boards as also for the Z170 gaming k3 board.
https://forums.guru3d.com/data/avatars/m/239/239175.jpg
Only Intruder:

Out of curiosity, I checked inspectre on my old Q6600 system, can confirm, it's vulnerable to Spectre and Meltdown (although meltdown has the os protection update). I wonder if I should pull my old Pentium 4 system out of storage and check that 😀?
The vulnerabilities affect CPUs all the way back to Pentium Pro. Not sure about the original Pentium. I think speculative execution was not part of the original Pentium.
https://forums.guru3d.com/data/avatars/m/247/247876.jpg
hawk7000:

Yes, the article confuses what Intel have released and what has so far been added to Microsoft's KB4090007 update. (I guess in a later update to KB4090007 all the microcode updates from Intel will be added.)
Robbo9999:

Yep, that is what will happen, I've bookmarked the KB4090007 page so I can click on it when I like to see if Sandybridge has been included: https://support.microsoft.com/en-gb/help/4090007/intel-microcode-updates
I have never heard of Microsoft altered already published KB. I would suggest that they just will publish new (cumulative) KB with microcodes for older CPUs (as well as ones from KB4090007). Anyway I will check this page instead https://support.microsoft.com/en-gb/help/4093836/summary-of-intel-microcode-updates
https://forums.guru3d.com/data/avatars/m/271/271258.jpg
KBDE:

Good read (especially towards the end, real world performance): https://www.pcworld.com/article/3250645/laptop-computers/how-meltdown-and-spectre-patches-drag-down-older-hardware.html To put it in perspective. My I7 2600k at 4800mhz with 28percent performance penalty equals a whopping 1344mhz frequency drop. meaning 3450mhz (instead of 4800mhz)!!! So yeah i've disabled this nonsense.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management]
"FeatureSettingsOverrideMask"=dword:00000003
"FeatureSettingsOverride"=dword:00000003
I've read this article and I can confirm that the responsiveness on my work notebook after both WU and BIOS updates is terrible, watching a video on youtube in 720p while trying to do other tasks on a core i5-4210U its a painful experience and the system's overall performance feel very sluggish and its really annoyng ... If on my 875k I feel a very notable performance drop especially in games, I will also undo this nonsense.
https://forums.guru3d.com/data/avatars/m/271/271612.jpg
mbk1969:

I have never heard of Microsoft altered already published KB. I would suggest that they just will publish new (cumulative) KB with microcodes for older CPUs (as well as ones from KB4090007). Anyway I will check this page instead https://support.microsoft.com/en-gb/help/4093836/summary-of-intel-microcode-updates
They have already done this for KB4090007 once, the initial version (1.001 in the table in the article) only had two variants of Skylake, now they have more Skylake variants and a bunch of the other *lakes (1.003 in the table in the article). The KB4090007 article also explicitly states "We will offer additional microcode updates from Intel thru this KB Article for these Operating Systems as they become available to Microsoft.", so I think we can be pretty sure they will just continue updating it, as they have already done once.
https://forums.guru3d.com/data/avatars/m/212/212547.jpg
hawk7000:

They have already done this for KB4090007 once, the initial version (1.001 in the table in the article) only had two variants of Skylake, now they have more Skylake variants and a bunch of the other *lakes (1.003 in the table in the article).
True story! The initial version had only two variants of Skylake and it was successfully installed in my Kabylake system. Today I checked the Microsoft update catalog and I found out that KB409007 contains more variants as well as my Kabylake. I re-downladed the update which was again successfully installed in my system. https://imgur.com/a/knsAt
https://forums.guru3d.com/data/avatars/m/247/247876.jpg
hawk7000:

They have already done this for KB4090007 once, the initial version (1.001 in the table in the article) only had two variants of Skylake, now they have more Skylake variants and a bunch of the other *lakes (1.003 in the table in the article). The KB4090007 article also explicitly states "We will offer additional microcode updates from Intel thru this KB Article for these Operating Systems as they become available to Microsoft.", so I think we can be pretty sure they will just continue updating it, as they have already done once.
Ok. We will see.
https://forums.guru3d.com/data/avatars/m/258/258664.jpg
KBDE:

Good read (especially towards the end, real world performance): https://www.pcworld.com/article/3250645/laptop-computers/how-meltdown-and-spectre-patches-drag-down-older-hardware.html To put it in perspective. My I7 2600k at 4800mhz with 28percent performance penalty equals a whopping 1344mhz frequency drop. meaning 3450mhz (instead of 4800mhz)!!! So yeah i've disabled this nonsense.
Thanks for the read. Still I'm more curious about gaming performance, as I personally don't do anything but game on my system. Anybody gotten some new benches so far?
https://forums.guru3d.com/data/avatars/m/238/238382.jpg
Do AMD cpu's not need microcode updates? For example the FX series.
https://forums.guru3d.com/data/avatars/m/63/63170.jpg
Well, I've just updated the BIOS's for two of my Boards, AsRock Z77 Pro4-m (running IvyBridge CPU) and Asus P8H77-I (Running SandyBridge CPU), using the UEFI BIOS Updater Tool. Will be flashing them tonight, and we will see what happens. Just hoping I don't brick the boards. Why am I not doing the Windows Update way ? I just want to have the option to install whatever OS I like later-on...
https://forums.guru3d.com/data/avatars/m/249/249226.jpg
"If you are on Windows 7 or 8.1, you'll need to wait until your motherboard manufacturers if and will release a firmware update to patch the vulnerabilities." They are slowly killing Win7? That's what all they want at the end? I don't know what to believe or trust anymore.... Stay away from KB4088875, they released a Monthly Rollup with so many known issues, listed as important? And now it's either unlisted or, listed but unticked?.. And if you uninstall KB4088875, it causes more problems?! https://www.computerworld.com/article/3263645/windows-pcs/microsoft-stops-pushing-buggy-win7-patch-kb-4088875-hopefully-as-a-precursor-to-yanking-it.html https://www.askwoody.com/2018/buggy-windows-7-monthly-rollup-kb-4088875-no-acknowledgment-from-microsoft/ I am on dual boot Win764 - Win10Pro and i am so tired of this.
https://forums.guru3d.com/data/avatars/m/239/239175.jpg
On my Linux install, the microcode update for my Sandy Bridge CPU has been already rolled out and installed three days ago. What's taking MS so long? 😛
$ cat /sys/devices/system/cpu/vulnerabilities/spectre_v2
Mitigation: Full generic retpoline, IBPB, IBRS_FW
Your MSIs and Gigabytes and Asuses are not going to care about this and start updating BIOSes for our $90, 8 year old mainboards. I just can't see that happening. MS needs to ship this in Windows ASAP, like Linux distros do. "But, but, maybe there's stability issues..." It's better to risk some possible instability than allowing people's computers to be turned into botnet zombies or bitcoin miners. The more time passes, the more ways to exploit the vulnerability are discovered.
data/avatar/default/avatar10.webp
I'm on skylake and still showing as unprotected with windows 10 1607 and all security updates installed.
https://forums.guru3d.com/data/avatars/m/227/227994.jpg
Yesterday evening i modded my BIOS and flashed to microcode 24 for my 4770K. Today i ran into and issue with uBlock Origin not wanting to load Custom Filters. I tried a manul update to the latest uBlock, and updated Chrome, but nothing helped. Guess what... it was the microcode for Spectre Variant 2 causing it. I just flashed back to microcode 22 and it's all working fine again.
https://forums.guru3d.com/data/avatars/m/212/212547.jpg
tensai28:

I'm on skylake and still showing as unprotected with windows 10 1607 and all security updates installed.
Do you have the latest bios(3703) for your board ?
https://forums.guru3d.com/data/avatars/m/222/222136.jpg
Good. Now I have a reason to push that 4.5GHz 2500k day 1 overclock (7 years in the making) further. I know she's capable of 4.8 but I'm thinking of going in balls deep at 5GHz.
data/avatar/default/avatar01.webp
Apparatus:

Do you have the latest bios(3703) for your board ?
Nope but I was reading this as the update makes it so the bios update isn't necessary. I don't want to install the new bios because it makes my system completely unstable and ruins my oc. I'd only install it if this threat became something serious.
https://forums.guru3d.com/data/avatars/m/271/271612.jpg
tensai28:

I'm on skylake and still showing as unprotected with windows 10 1607 and all security updates installed.
Specifically wrt Spectre? Did you install an UEFI/BIOS update that has the updated microcode? If not, I would think that there is no way for you to have the updated microcode at this point. The Microsoft delivered microcode update is still a manual download at this point and only available for the current Windows 10 version (1709). Edit: See https://support.microsoft.com/en-gb/help/4093836/summary-of-intel-microcode-updates for links to relevant downloads
data/avatar/default/avatar04.webp
hawk7000:

Specifically wrt Spectre? Did you install an UEFI/BIOS update that has the updated microcode? If not, I would think that there is no way for you to have the updated microcode at this point. The Microsoft delivered microcode update is still a manual download at this point and only available for the current Windows 10 version (1709).
Well the article says this
Put short, these patches will make your PC safer, even without a mandatory firmware update. To be able to retrieve the patches, you must have Windows 10 installed with build 1607/1703 or 1709.
So I'm interpreting it as; no bios update needed as long as you have windows 10 1607 and up. Hopefully I'm correct on that. So if there's only a patch for 1709, does that mean us on 1607 have to wait? If so, I'm fine with waiting.
https://forums.guru3d.com/data/avatars/m/271/271612.jpg
tensai28:

Well the article says this So I'm interpreting it as; no bios update needed as long as you have windows 10 1607 and up. Hopefully I'm correct on that. So if there's only a patch for 1709, does that mean us on 1607 have to wait? If so, I'm fine with waiting.
It seems like this is what should be applicable to 1607: https://support.microsoft.com/en-us/help/4091664 Is that what you have installed?