Results 1 to 10 of 10

Thread: Spectre / Meltdown chip bugs and Linux?

  1. #1
    Join Date
    Jun 2008
    Location
    Prescott, AZ
    Posts
    1,175

    Default Spectre / Meltdown chip bugs and Linux?

    Does anyone know how the linux community has/is responding to this?
    TY, Pattim

    https://krebsonsecurity.com/2018/01/...wn/#more-42139

    The Meltdown bug affects every Intel processor shipped since 1995 (with the exception of Intel Itanium and Intel Atom before 2013), although researchers said the flaw could impact other chip makers. Spectre is a far more wide-ranging and troublesome flaw, impacting desktops, laptops, cloud servers and smartphones from a variety of vendors.


    Patches to address this flaw in Linux systems were released last month.

  2. #2
    Join Date
    Jun 2008
    Location
    Auckland, NZ
    Posts
    20,371
    Blog Entries
    1

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Yes, lots of discussion both here and outside the forums if you search. Some patches released already. Have you fully updated your system(s) yet?

    https://news.opensuse.org/2018/01/04...lnerabilities/

  3. #3
    Join Date
    Jun 2008
    Location
    Podunk
    Posts
    26,795
    Blog Entries
    15

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Quote Originally Posted by PattiMichelle View Post
    Does anyone know how the linux community has/is responding to this?
    TY, Pattim

    https://krebsonsecurity.com/2018/01/...wn/#more-42139

    The Meltdown bug affects every Intel processor shipped since 1995 (with the exception of Intel Itanium and Intel Atom before 2013), although researchers said the flaw could impact other chip makers. Spectre is a far more wide-ranging and troublesome flaw, impacting desktops, laptops, cloud servers and smartphones from a variety of vendors.


    Patches to address this flaw in Linux systems were released last month.
    Hi
    Your about two weeks late... Updates have been done and released, still a few niggles around though. Might have to get microcode updates from your cpu vendor...

    Worth a read;
    http://forums.opensuse.org/showthread.php?t=528900
    https://www.suse.com/c/suse-addresse...lnerabilities/
    https://www.suse.com/support/kb/doc/?id=7022512 (maybe slow if it's being updated)
    https://www.techarp.com/guides/compl...ctre-cpu-list/
    Cheers Malcolm °¿° SUSE Knowledge Partner (Linux Counter #276890)
    SUSE SLE, openSUSE Leap/Tumbleweed (x86_64) | GNOME DE
    If you find this post helpful and are logged into the web interface,
    please show your appreciation and click on the star below... Thanks!

  4. #4
    Join Date
    Jun 2008
    Location
    Auckland, NZ
    Posts
    20,371
    Blog Entries
    1

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Just one of a number of threads...
    https://forums.opensuse.org/showthre...wn-and-Spectre

  5. #5
    Join Date
    Jun 2008
    Location
    Prescott, AZ
    Posts
    1,175

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Thanks for the links, Malcom. I get confused by email chains and prefer such links.

    Quote Originally Posted by malcolmlewis View Post
    Hi
    Your about two weeks late... Updates have been done and released, still a few niggles around though. Might have to get microcode updates from your cpu vendor...

    Worth a read;
    http://forums.opensuse.org/showthread.php?t=528900
    https://www.suse.com/c/suse-addresse...lnerabilities/
    https://www.suse.com/support/kb/doc/?id=7022512 (maybe slow if it's being updated)
    https://www.techarp.com/guides/compl...ctre-cpu-list/

  6. #6
    Join Date
    Jun 2008
    Location
    Prescott, AZ
    Posts
    1,175

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Quote Originally Posted by deano_ferrari View Post
    I *still* wish there was a "Security" forum on here...

    Apparently these sorts of issues are highly regarded as threats to our global system...
    http://reports.weforum.org/global-ri...-infographics/
    http://reports.weforum.org/global-ri...-and-failures/

  7. #7
    Join Date
    Jun 2008
    Location
    Podunk
    Posts
    26,795
    Blog Entries
    15

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Quote Originally Posted by PattiMichelle View Post
    I *still* wish there was a "Security" forum on here...

    Apparently these sorts of issues are highly regarded as threats to our global system...
    http://reports.weforum.org/global-ri...-infographics/
    http://reports.weforum.org/global-ri...-and-failures/
    Hi
    Realistically if someone has physical access to your hardware... nothing is safe...

    Your more likely to have your details and information leaked by a third party...
    Cheers Malcolm °¿° SUSE Knowledge Partner (Linux Counter #276890)
    SUSE SLE, openSUSE Leap/Tumbleweed (x86_64) | GNOME DE
    If you find this post helpful and are logged into the web interface,
    please show your appreciation and click on the star below... Thanks!

  8. #8
    Join Date
    Jun 2008
    Location
    Prescott, AZ
    Posts
    1,175

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Quote Originally Posted by malcolmlewis View Post
    Hi
    Realistically if someone has physical access to your hardware... nothing is safe...

    Your more likely to have your details and information leaked by a third party...
    The whole Win* and Mac infosphere is beyond fragile - I see it as sort of emblematic of the overall failure of the for-profit approach.
    I shudder every time I see someone banking using a cell phone or Win/Mac.
    And most of our banks are either Windows or Mac based, I think.

    I was just curious how the linux infosphere was doing on this - Krebsonsecurity is all about Win/Mac, so it's hard to get equivalently in-depth information for linux.

  9. #9
    Join Date
    Jun 2008
    Location
    Auckland, NZ
    Posts
    20,371
    Blog Entries
    1

    Default Re: Spectre / Meltdown chip bugs and Linux?

    Quote Originally Posted by PattiMichelle View Post
    The whole Win* and Mac infosphere is beyond fragile - I see it as sort of emblematic of the overall failure of the for-profit approach.
    I shudder every time I see someone banking using a cell phone or Win/Mac.
    And most of our banks are either Windows or Mac based, I think.

    I was just curious how the linux infosphere was doing on this - Krebsonsecurity is all about Win/Mac, so it's hard to get equivalently in-depth information for linux.
    Apart from the mailing lists (which I tend not to frequent), here's some good websites....

    http://www.zdnet.com/topic/linux/
    In particular
    http://www.zdnet.com/article/major-l...rt-of-the-fix/

    http://www.linuxsecurity.com/content...egory/100/112/
    In particular
    http://www.linuxsecurity.com/content/view/209855/170/

    https://www.linuxtoday.com/security/

    Of general interest...
    https://www.theverge.com/2018/1/11/1...icrosoft-linux

  10. #10
    Join Date
    Apr 2016
    Location
    North America
    Posts
    537

    Default Re: Spectre / Meltdown chip bugs and Linux?


Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •