When will the Azure DC*s machines with SGX get a firmware update to mitigate INTEL-SA-00828 aka downfall aka GDS

Harald Hoyer 15 Reputation points
2023-08-10T09:35:20.56+00:00

With the Intel CPU vulnerability INTEL-SA-00828 aka downfall it is critical for SGX applications to run on an updated machine.

Where can I get information about planned firmware updates on the Azure machines running the hypervisor?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,175 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. deherman-MSFT 33,626 Reputation points Microsoft Employee
    2023-08-14T16:10:00.88+00:00

    @Harald Hoyer

    Microsoft is aware of recent reports discussing CVE-2022-40982 affecting certain Intel CPUs as described in SA-00828. We have evaluated the issue and have determined that there are no customer actions required for the majority of scenarios, only those customers who have opted-out of automatic updates with custom maintenance configurations need to take action.

    Frequently asked questions:
    Q: Which Azure service does this vulnerability affect?
    A: This vulnerability affected certain Virtual Machine SKUs using Intel processors with the "Ice Lake", "Cascade Lake", and "Skylake" architectures. More information about affected chipsets can be found in Intel's disclosure.

    Q: How is Microsoft mitigating this vulnerability in Azure?
    A: We have rolled out updates to our cloud infrastructure to patch this vulnerability. For the majority of customers, this was a background update that would have not resulted in service interruption or performance degradation. However, a small subset of customers with custom Maintenance Configurations on their VMs may need to take additional action to apply the update.

    Q: Is there any action customers need to take?
    A: For the majority of customers, the mitigation was applied as a background update and no further action is required. A small subset of customers who have configured custom Maintenance Configurations on their VMs to suspend updates will need to take additional action to apply the update. These customers were sent notifications through Service Health in the Azure Portal under tracking ID RKRB-VT0 with further guidance.
    ===========

    Referenced content:

    Microsoft: Control updates with Maintenance Configurations and the Azure portal
    PC MagIntel Patches 'Critical Weakness' Found in Billions of Processors
    **Intel: **Gather Data Sampling / CVE-2022-40982 / INTEL-SA-00828


    If you still have questions, please let us know in the "comments" and we would be happy to help you. Comment is the fastest way of notifying the experts.

    If the answer has been helpful, we appreciate hearing from you and would love to help others who may have the same question. Accepting answers helps increase visibility of this question for other members of the Microsoft Q&A community.

    Thank you for helping to improve Microsoft Q&A! User's image

    2 people found this answer helpful.