cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
Highlighted
D000D
Punch Card
Posts: 28
Location: US
Views: 5,345
Message 11 of 33

Re: BIOS updates for Meltdown and Spectre

I'm also wondering about a BIOS update for the Yoga 2 Pro Laptop (Machine Type Model: 80AY59394167). Come on Lenovo; please provide some information.
SeniorGuru
Posts: 1,812
Location: US
Views: 5,331
Message 12 of 33

Re: BIOS updates for Meltdown and Spectre

I have been watching threads, talking with my friends at intel and AMD... Mostly they are stating that Meltdown will require an "overhaul" of the entire CPU design to fix, while Scepter can be addressed via software patches.

For the most part most of the patches will be coming soon to deal with scepter, the meltdown bug will take some time to remove.

CB

I do not work for Lenovo, I only provide suggestions based on my personal willingness to help others. All advice and comments are based on my experience, and do not reflect Lenovo policy, terms or conditions.
Birraque
Token Ring
Posts: 191
Location: BR
Views: 5,324
Message 13 of 33

Re: BIOS updates for Meltdown and Spectre

[Moderator Note:  Posting edited to conform to the Community Guidelines.]

 

Dear goretsky,

 

While Intel has now issued Firmware updates for CPUs introduced in the past 5 years, Lenovo Yoga 2 Pro (20266) - Intel Core i7 4500U Haswell with "only" 3 years old isn't even listed under Lenovo End-Of-Life List or Lenovo Security Advisory LEN-18282 (NO ETA FOR US) as detailed HERE.

Please Lenovo keep us safe supporting your costumers with a proper Firmware update to address Spectre ASAP.

Best Regards,

Carl_L
What's DOS?
Posts: 1
Location: SE
Views: 5,243
Message 14 of 33

Re: BIOS updates for Meltdown and Spectre

Great to hear that these updates are being worked on!

 

However, the list at https://support.lenovo.com/se/sv/solutions/len-18282 doesn't seem very well-sorted. Some models are listed with their complete name (like "Lenovo ideapad 320-17IKB/520-15IKB") and some are just the model numbers which results in an unsorted list that makes it unnecessarily difficult to find things.

 

Myself, I have a Lenovo IdeaPad 310-15ISK and I am unsure if it is unlisted on this page (which would suck) or if it's the same as the "V310-15ISK" that IS listed. Does the "V" stand for "version" so that this is the same model version as I have, or is it a totally different model? [If it's a different model, please Lenovo: never name your models like that again, because starting the name with a "V" before a number series almost always means "version" so don't confuse people by naming models that way, if you mean something completely different!!]

 

Since my current bios is named 0XCN37WW and the "V310-15ISK" bios is called 0ZCN44WW ("Z" instad of "X"), I'm guessing that they are two totally different models. Which would lead to the question: is an update being looked at for the IdeaPad 310-15ISK? Could it be added to the page above, with an ETA for the security update?

 

When inspecting my computer with InSpectre, it shows me what protection is present for the system and what is still lacking. As can be seen, the protection that is missing is the bios update.InSpectre01.png

 

InSpectre02.png

 

 

 

Community SeniorMod
Community SeniorMod
Posts: 3,067
Location: US
Views: 5,235
Message 15 of 33

Re: BIOS updates for Meltdown and Spectre

Hello,

 

Intel has asked companies like Dell, HP and Lenovo to withdraw them because of quality issues:

 

https://newsroom.intel.com/news/intel-security-issue-update-addressing-reboot-issues/

 

Remember, even after Intel does get things correct, Lenovo should take some time to verify the quality of microcode before releasing it.  If your system randomly blue screens because of the patch, that's not a great outcome for everyone involved (Intel, Lenovo and, most importantly, you).

 

Regards,

 

Aryeh Goretsky

 

 


@Birraque wrote:

Dear goretsky,

 

While Intel has now issued Firmware updates for CPUs introduced in the past 5 years, Lenovo Yoga 2 Pro (20266) - Intel Core i7 4500U Haswell with "only" 3 years old isn't even listed under Lenovo End-Of-Life List or Lenovo Security Advisory LEN-18282 (NO ETA FOR US) as detailed HERE.

Please Lenovo keep us safe supporting your costumers with a proper Firmware update to address Spectre ASAP.

Best Regards,


 



I am a volunteer and neither a Lenovo nor a Microsoft employee.

L380 YogaP50 (20EN-*)S230u (3347-4HU)T23 (2648-LU7)T42 (2378-R4U)T43p (2678-H7U)T61p (6459-CTO)W510 (4318-CTO)W530 (2441-4R3)W530 (2441-4R3)X100e (3508-CTO)X120e (0596-CTO)X220 (4286-CTO)X250 (20CM-*)Yoga 370

de.gif Deutsche Community es.gif Comunidad en Español ru.gif Русскоязычное Сообщество pt.gif Communidade Portugues
thanos28
Paper Tape
Posts: 1
Location: GR
Views: 5,171
Message 16 of 33

Re: BIOS updates for Meltdown and Spectre

Seems like https://support.lenovo.com/gr/el/solutions/len-18282 has changed it's layout and there is no list at this moment, also would Lenovo release a patch for Ideapad Y450? My system is only vulnerable to Spectre.

Birraque
Token Ring
Posts: 191
Location: BR
Views: 5,159
Message 17 of 33

Re: BIOS updates for Meltdown and Spectre

Dear goretsky,

Thanks for your reply.
Seems 'Lenovo Security Advisory LEN-18282' ( https://support.lenovo.com/us/en/solutions/len-18282 ) disappeared and is now redirect to a "Standard" 'Lenovo Support Site' ( https://download.lenovo.com/supportdata/index.html ) not related to address Spectre & Meltdown vulnerabilities.

Support.PNGLAPTOPS-AND-NETBOOKS \ YOGA-SERIES \ YOGA-2-PRO-LENOVO

 

Support_Y2P.PNGLAPTOPS-AND-NETBOOKS \ YOGA-SERIES \ YOGA-2-PRO-LENOVO; Yoga 2 Pro (20266) Available BIOS 76CN43WW Updated Date 2015/04/27


What I realy would like to know is a simple and direct answer if LENOVO YOGA 2 PRO (20266 /80AY) 'WILL' or 'WILL NOT' receive a 'NEW Firmware' from Lenovo and the 'ETA'.
Could you please push Lenovo Engineering Team to provide this clarification statement?


Regards,

EDIT: NEW link to Lenovo Security Advisory: LEN-18282 (for Ideapad \ Yoga) and YOGA 2 PRO (20266) still isn't even listed under it.

flaphoschi
Blue Screen Again
Posts: 2
Location: DE
Views: 5,164
Message 18 of 33

SPECTRE FIXES canceled for X220, T420 and W520?

Hello Lenovo!

 

I expected to see a new BIOS-Update for my X220 at end of february:

 

Screenshot-2018-1-15 Reading Privileged Memory with a Side Channel.png

https://support.lenovo.com/de/en/solutions/len-18282

 

I was glad to see that, because Intel is just unable to make any clear statement and refuses to fix older CPUs. This is now removed, without a notice!

 

Dangerous security issues must be always fixed, there is not out of support in general. Despite that, the X220 was sold till 2013 and 2018 is in the ususal five year warranty range of the ThinkPads.

 

Can you tell us please, what is going on? I hope you will follow your own path of good support and not Intel. Interestingly there are still listed Microcodeupdates for SandyBridge (Server), same architecture.

 

Thanks

Chawa
Fanfold Paper
Posts: 3
Location: SI
Views: 4,686
Message 19 of 33

Re: BIOS updates for Meltdown and Spectre

some news for y510p new BIOS patch?

Onepamopa
Punch Card
Posts: 24
Location: BG
Views: 4,573
Message 20 of 33

Re: BIOS updates for Meltdown and Spectre

Im wondering the same thing - Will there be a bios update for Y510p ????
Top Kudoed Authors