General information

August 19, 2026 · View on GitHub

Intel and AMD CPU generations; Transient execution CPU vulnerability.

"ESU" means "End of Servicing Updates" -- the date after which Intel stops releasing microcode for a CPU generation; newly discovered vulnerabilities on past-ESU generations remain unpatched. The EOL_ prefix in board directories indicates ended microcode servicing. For future ESU dates refer to:

Per-board EOL/ESU status

The Last Microcode column links to the Intel microcode releases page. Dates below are as of the document's last update and may be stale.

EOL boards (EOL_ prefix present):

BoardGenCode NameESU DateLast Microcode
EOL_t4202ndSandy BridgeNo official ESU2019-05-14
EOL_x2202ndSandy BridgeNo official ESU2019-05-14
EOL_t4303rdIvy BridgeNo official ESU2019-05-14
EOL_w5303rdIvy BridgeNo official ESU2019-05-14
EOL_x2303rdIvy BridgeNo official ESU2019-05-14
EOL_t5303rdIvy BridgeNo official ESU2019-05-14
EOL_optiplex-7010_90103rdIvy BridgeNo official ESU2019-05-14
EOL_z220-cmt3rdIvy BridgeNo official ESU2019-05-14
EOL_t440p4thHaswellJun 30, 20212021-06
EOL_w5414thHaswellJun 30, 20212021-06
EOL_librem_l1um5thBroadwellJun 30, 20212020-06
EOL_librem_13v26thSkylakeSep 30, 20222022-11
EOL_librem_15v36thSkylakeSep 30, 20222022-11
EOL_m900_tower6thSkylakeSep 30, 20222022-11
EOL_librem_13v47thKaby LakeMar 31, 20242024-03
EOL_librem_15v47thKaby LakeMar 31, 20242024-03
EOL_t4808thKaby Lake-RMar 31, 2026 ¹2024-03
EOL_t480s8thKaby Lake-RMar 31, 2026 ¹2024-03

¹ KBL-R falls under Whiskey Lake ESU (Mar 31, 2026); also classified under Coffee Lake ESU (Jun 30, 2025). Both dates have passed.

| librem_l1um_v2 | 9th | Coffee Lake Refresh | Jun 30, 2026 | Not in Feb 2026+ | | librem_mini | 8th | Whiskey Lake | Mar 31, 2026 | Not in Feb 2026+ | | UNTESTED_talos-2 | POWER9 | Talos II (IBM) | Jan 31, 2026 ² | Feb 2024 ² |

² IBM End of Standard Service for POWER9. Last Raptor firmware release: February 2024.

Active boards (ESU not yet reached; no EOL_ prefix):

BoardGenCode NameESU DateLast Microcode
librem_1410thComet LakeJun 30, 20272025-05 ³
librem_mini_v210thComet LakeJun 30, 20272025-05 ³
librem_11AtomJasper LakeTBDTBD
UNTESTED_nitropad-ns5012thAlder LakeActive2026-02
novacustom-nv4x_adl12thAlder LakeActive2026-02
UNTESTED_msi_z690a_ddr412thAlder LakeActive2026-02
UNTESTED_msi_z690a_ddr512thAlder LakeActive2026-02
msi_z790p_ddr513thRaptor LakeActive2026-05
UNTESTED_msi_z790p_ddr413thRaptor LakeActive2026-05
novacustom-v540tuCore Ultra S1Meteor LakeActive2026-05
novacustom-v560tuCore Ultra S1Meteor LakeActive2026-05

³ Comet Lake ESU runs through Jun 30, 2027. Check the Intel microcode releases page for recent updates.

Formerly supported (unmaintained_boards/*/; reference only):

BoardGenCode NameESU DateLast Microcode
KGPE-D16AMD Family 15hBulldozerNo AMD ESU2018-05 (dropped in coreboot 4.12)

KGPE-D16 is the last fully blob-free x86 platform (Talos II is the last fully blob-free platform overall, on POWER9). AMD ceased Family 15h microcode in 2018; removed from upstream coreboot in 4.12 (2019). The Dasharo fork was abandoned August 2025. An independent community port (15h.org, October 2025) exists but is not part of upstream coreboot.

Mitigation

Spectre Variant 2 (CVE-2017-5715) and related speculative execution vulnerabilities are unpatched on any board past its ESU date. Retpoline and similar software mitigations have limited effectiveness without microcode updates. On EOL platforms, run a single trusted workflow per boot session and reboot before switching tasks.

See the Heads threat model for detailed guidance including Tails OPSEC, QubesOS memory management, and QSB-107 exposure rates.

TPM GPIO Reset Vulnerability

Many Intel platforms are vulnerable to a TPM GPIO reset bypass (mkukri.xyz, 2024). See the Heads Wiki Threat Model for per-platform status and mitigation. Test with:

tpm-gpio-detect 2>&1 | tee /media/tpm-gpio-detect.log
tpm-gpio-assert 2>&1 | tee /media/tpm-gpio-assert.log

The TPM Reset clears all PCRs to zero. A subsequent attacker would need to replay known PCR measurements to reconstruct the sealed state and extract TOTP/HOTP shared secrets -- this PoC proves the reset is possible but does not perform PCR replay.

The TPM Disk Unlock Key with passphrase is not affected -- the passphrase is required regardless of PCR state. TPMTOTP/HOTP remote attestation is affected -- the shared secret at NVRAM index 0x4d47 has no passphrase, enabling unseal with forged PCRs.

The fix must come from coreboot. Tracked at coreboot ticket #576 and coreboot patch series.

Board Testers

Boards under boards/* must be tested by listed owners for coreboot/linux version bumps. This file is the primary board tester registry. To be added or removed as a tester, comment on issue #692. For HCL details: boards/BOARD_NAME/BOARD_NAME.config.

Laptops

xx20 (Sandy Bridge, 2nd Gen -- EOL)

  • t420 (xx20): @notgivenby @alexmaloteaux @akfhasodh @doob85
  • x220 (xx20): @srgrint @Thrilleratplay

xx30 (Ivy Bridge, 3rd Gen -- EOL)

  • t430 (xx30): @notgivenby @nestire @Thrilleratplay @alexmaloteaux @lsafd @bwachter(iGPU maximized) @shamen123 @eganonoa(iGPU) @nitrosimon @jans23 @icequbes1 (iGPU) @weyounsix (t430-dgpu)
  • w530 (xx30): @eganonoa @zifxify @weyounsix (dGPU: w530-k2000m) @jnscmns (dGPU K1000M) @computer-user123 (w530 / w530 k2000: prefers iGPU) @tlaurion
  • x230 (xx30): @nestire @tlaurion @merge @jan23 @MrChromebox @shamen123 @eganonoa @bwachter @Thrilleratplay @jnscmns @makkiato83
  • x230-fhd/edp variant: @n4ru @computer-user123 (nitro caster board) @Tonux599 @househead @pcm720 (eDP 4.0 board and 1440p display) @doob85
  • t530 (xx30): @fhvyhjriur @3hhh (See: https://github.com/linuxboot/heads/issues/1682)

ThinkCentre (Skylake, 6th Gen Desktop -- EOL)

  • M900 Tower: @notgivenby

xx4x (Haswell, 4th Gen -- EOL)

  • t440p: @MattClifton76 @fhvyhjriur @ThePlexus @srgrint @akunterkontrolle @rbreslow
  • w541 (similar to t440p): @gaspar-ilom @ResendeGHF

xx8x (Kaby Lake Refresh, 8th Gen Mobile -- EOL)

  • t480: @gaspar-ilom @doritos4mlady @MattClifton76 @notgivenby @akunterkontrolle @nestire (Nitrokey)
  • t480s: @thickfont @kjkent @HarleyGodfrey @nestire (Nitrokey)

Librem

All EOL unless marked Active.

  • Librem 13v2 (Skylake, 6th Gen): @JonathonHall-Purism
  • Librem 15v3 (Skylake, 6th Gen): @JonathonHall-Purism
  • Librem 15v4 (Kaby Lake, 7th Gen): @JonathonHall-Purism
  • Librem 13v4 (Kaby Lake, 7th Gen): @JonathonHall-Purism
  • Librem 14 (Comet Lake, 10th Gen -- Active): @JonathonHall-Purism
  • Librem 11 (Jasper Lake, Atom -- Active): @JonathonHall-Purism

Clevo

All Active.

  • Nitropad NS50 (Alder Lake, 12th Gen): @daringer
  • Novacustom NV4x (Alder Lake, 12th Gen): @tlaurion @daringer
  • Novacustom v540tu (Meteor Lake, Core Ultra S1): @tlaurion @daringer @mkopec
  • Novacustom v560tu (Meteor Lake, Core Ultra S1): @tlaurion @daringer @mkopec

Desktops / Servers

All EOL unless marked Active.

  • Optiplex 7010/9010 SFF/DT (Ivy Bridge, 3rd Gen): @tlaurion(owns DT variant)
  • HP Z220 CMT (Ivy Bridge, 3rd Gen): @d-wid
  • KGPE-D16 (AMD Family 15h): @arhabd @Tonux599 @zifxify
  • Librem L1UM v1 (Broadwell, 5th Gen): @JonathonHall-Purism
  • Librem L1UM v2 (Coffee Lake, 9th Gen): @JonathonHall-Purism
  • Librem mini v1 (Whiskey Lake, 8th Gen): @JonathonHall-Purism
  • Librem mini v2 (Comet Lake, 10th Gen -- Active): @JonathonHall-Purism
  • Talos II (POWER9, PPC64LE): @tlaurion (became untested, low community interest despite large investment)

MSI (Alder/Raptor Lake — Active)

  • MSI PRO Z690-A (WIFI) (DDR4): None - Board is untested. (Active, Alder Lake 12th Gen)
  • MSI PRO Z690-A (WIFI) (DDR5): None - Board is untested. (Active, Alder Lake 12th Gen)
  • MSI PRO Z790-P (WIFI) (DDR4): None - Board is untested. (Active, Raptor Lake 13th Gen)
  • MSI PRO Z790-P (WIFI) (DDR5): @Tonux599 (Active, Raptor Lake 13th Gen)