ProLiant Servers (ML,DL,SL)
1753479 Members
4978 Online
108794 Solutions
New Discussion юеВ

Re: DL180 G6 Meltdown and Spectre Bios Update

 
jvang
Frequent Visitor

DL180 G6 Meltdown and Spectre Bios Update

According to the Meltdown/Spectre Customer Bulletin, it sounds as if all of the G6 bios have been posted, but I'm not finding the BIOS for the DL180 G6 either on that page or on the DL180 G6 support page.  The E5606 processor for our specific server is listed under the Intel Microcode Update Guidance documentation as in "Production."

Refer to the following table for a list of System ROM revisions that include updated microcodes For Gen10, Gen9, Gen8, G7 and G6 platforms.

Question: For HPE ProLiant and Synergy platforms, does HPE intend to release System ROM updates including mitigations for Spectre Variant 2 for server generations earlier than G6?

Answer: HPE will release System ROM updates for ProLiant and Synergy platforms for which processor vendors make microcode updates available to mitigate Spectre Variant 2. Intel has released microcodes with mitigations for G6 and newer servers, and HPE has made System ROM updates available for all G6 and newer platforms using the ProLiant System BIOS. Intel currently does not plan to release additional microcode updates for older processors. Information on Intel├втВмтДвs release plans for microcodes related to Spectre Variant 2 can be found in Intel├втВмтДвs Microcode Revision Guidance Non-HPE site .

I know with the new Variant 3a and 4, this BIOS release may get pushed back.  Is there an ETA for the BIOS update for the Meltdown/Spectre security issue?  Please confirm if there will be an updated BIOS for the DL180 G6 server.  Thanks.

7 REPLIES 7
ukguy
Occasional Advisor

Re: DL180 G6 Meltdown and Spectre Bios Update

same here, proliant g6 320, can't find the bios / rom updates anywhere.

We recently updated to the "pre-g9" esxi may 2018 release, I thought that would protect it but it doesn't. Tests still show no protection. This is the last pre-gen9 update so I persume the bios will be a separate rom update?

Very fragmented info here.

ukguy
Occasional Advisor

Re: DL180 G6 Meltdown and Spectre Bios Update

https://newsroom.intel.com/wp-content/uploads/sites/11/2018/04/microcode-update-guidance.pdf

Searching here, the bios for my cpu are available, you can check yours

NO idea where to get these though and when or where HP are making them available?

ukguy
Occasional Advisor

Re: DL180 G6 Meltdown and Spectre Bios Update

ok i may have found them.... see here https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c00308226

scroll down and find your processor, mine is 320 g6

https://support.hpe.com/hpsc/swd/public/detail?swItemId=MTX_d44f3450fa734874b76352a638&lang=en-us&cc=us

click on revision history

it says

Version:2018.02.22(A) (22 Mar 2018)

Fixes

Upgrade Requirement:
Critical - HPE requires users update to this version immediately.

"provides mitigation for Variant 2 of the Side Channel Analysis vulnerability, also known as Spectre"

only thing is the listed operating systems don't include esxi/vmware, so I"m unsure, but I"m nearer!

 

ukguy
Occasional Advisor

Re: DL180 G6 Meltdown and Spectre Bios Update

ok clicking on the update does show esxi 4 but i guess that's from the original supported operating systems in 2009

ukguy
Occasional Advisor

Re: DL180 G6 Meltdown and Spectre Bios Update

follow up for anyone finding this - doesn't work executing on esxi via ssh - it seems to only be the usb version. Guess we wait and watch.... this is a time consuming nightmare!

Nico57
Advisor

Re: DL180 G6 Meltdown and Spectre Bios Update

Don't hold your breath.

HPE explicitely said they won't be providing any BIOS/microcode update for the DL180 G6 series.

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us

ZNikke
Occasional Visitor

Re: DL180 G6 Meltdown and Spectre Bios Update

Yeah, this is the same reply I got from HPE support before the advisory was updated with the DL1xxG6 models. Basically, it sucks.

Has anyone tried applying the latest Intel microcode from the OS on these machines? The update for the 56xx CPUs is not included in the Debian/Ubuntu packages due to potential issues with an older (2011)  Intel issue SA-00030. See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=907402 for details. However, our DL180G6:s has the latest release BIOS dated 07/01/2013 installed which theoretically should contain the prerequisities needed for the current firmware?

I quickly looked at RHEL 6/7 and the latest firmware for the 56xx CPUs seems to be missing there as well...