By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Intel SGX “EUPDATESVN” Support Queued For Linux 6.19 As A Feature Since Ice Lake
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Intel SGX “EUPDATESVN” Support Queued For Linux 6.19 As A Feature Since Ice Lake
Computing

Intel SGX “EUPDATESVN” Support Queued For Linux 6.19 As A Feature Since Ice Lake

News Room
Last updated: 2025/10/28 at 9:26 AM
News Room Published 28 October 2025
Share
SHARE

An improvement to Intel SGX slated for Linux 6.18 is supporting the EUPDATESVN found on Intel CPUs since the Ice Lake generation. EUPDATESVN allows for updating the security SVN version after run-time patching for addressing any Intel SGX vulnerabilities to avoid having to carry out a platform reboot.

This automatic SVN updates for Software Guard Extensions (SGX) enclaves with EUPDATESVN on Ice Lake CPUs and newer is intended to avoid having the hassles/challenges of downtime in needing to otherwise reboot the platform when needing to update the software for SGX vulnerabilities.

Intel Xeon Ice Lake CPU

The prior patch series for this work explains:

“In case an SGX vulnerability is discovered and TCB recovery for SGX is triggered, Intel specifies a process that must be followed for a given vulnerability. Steps to mitigate can vary based on vulnerability type, affected components, etc. In some cases, a vulnerability can be mitigated via a runtime recovery flow by shutting down all running SGX enclaves, clearing enclave page cache (EPC), applying a microcode patch that does not require a reboot (via late microcode loading) and restarting all SGX enclaves.

Problem statement
————————-
Even when the above-described runtime recovery flow to mitigate the SGX vulnerability is followed, the SGX attestation evidence will still reflect the security SVN version being equal to the previous state of security SVN (containing vulnerability) that created and managed the enclave until the runtime recovery event. This limitation currently can be only overcome via a platform reboot, which negates all the benefits from the rebootless late microcode loading and not required in this case for functional or security purposes.

Proposed solution
—————–

SGX architecture introduced a new instruction called EUPDATESVN to Ice Lake. It allows updating security SVN version, given that EPC is completely empty. The latter is required for security reasons in order to reason that enclave security posture is as secure as the security SVN version of the TCB that created it.

This series enables opportunistic execution of EUPDATESVN upon first EPC page allocation for a first enclave to be run on the platform.”

These patches are now queued into tip/tip.git’s x86/sgx branch. With the patches now in a TIP branch, they should be submitted for the upcoming Linux 6.19 merge window.

EUPDATESVN patches queued

Yes, Intel Xeon Ice Lake processors are approaching five years of age and these Linux kernel patches for EUPDATSVN usage have been a long time coming. They’ve been worked on by multiple different Intel Linux developers over time and went through 17 rounds of patch review before working them into this form for now being able to make it into the mainline Linux kernel if all goes well for Linux 6.19.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article 5 Steam Deck Accessories On Amazon That Customers Swear By – BGR
Next Article Our Favorite Heated Blankets for Cozy Winter Nights
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

iOS 26.1 will add four new ways to customize your iPhone – 9to5Mac
News
Boox Palma 2 Pro vs Kindle Colorsoft: Comparing the e-ink tablets
Gadget
How Did Mars Get Its Moons? – BGR
News
Razer’s new Huntsman V3 Pro 8kHz keyboard promises speed with improved typing feel
News

You Might also Like

Computing

DM-VERITY Change For Linux 6.19: “On Some CPUs This Nearly Doubles Hashing Performance”

2 Min Read
Computing

NVIDIA RTX 5060 reportedly launching on May 19, priced at around $349 · TechNode

1 Min Read
Computing

Access’s Hydrogen quadruples profit on 197% transaction surge

3 Min Read
Computing

Microsoft’s SAMBA Model Redefines Long-Context Learning for AI | HackerNoon

9 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?