Meltdown/Spectre vulnerabilities and Tumbleweed

I just read in opensuse news that the long-term support 4.4 kernel has been patched against Meltdown/Spectre vulnerabilities, but that the 4.14.12 kernel hasn’t.

https://news.opensuse.org/2018/01/11/new-python3-libreoffice-google-re2-packages-released-in-tumbleweed/

I also read that Intel has released a new microcode patch to address Meltdown/Spectre –

http://news.softpedia.com/news/intel-releases-processor-microcode-patch-for-linux-oses-here-s-how-to-update-519316.shtml

– and that this microcode is available in the openSUSE repositories.

http://news.softpedia.com/news/opensuse-tumbleweed-now-patched-against-meltdown-spectre-adopts-libreoffice-6-0-519339.shtml

So-oo, I took a look in Yast, found ucode-intel with a date of 20171117-2.1. I tried to update; nothing happened. Will a later version arrive with upcoming Tumbleweed snapshots? Will I even need to care about the microcode, if an upcoming kernel addresses Meltdown/Spectre in other ways?

Fellow Tumblweed users, I’m confused about what to do, if anything! I know a rolling distro lives in a different world than conventional releases. How are you dealing with the vulnerability on your systems?

That must be a mistake.
Both 4.14.11 and 4.14.12 do have patches for these vulnerabilities, they even caused problems for users (32bit applications crashing on AMD CPUs, system not booting/freezing).
4.14.13 should have some more fixes (for the problems in particular).

So-oo, I took a look in Yast, found ucode-intel with a date of 20171117-2.1. I tried to update; nothing happened. Will a later version arrive with upcoming Tumbleweed snapshots?

The latest update is in the queue and should be in one of the next Tumbleweed snapshots.

IIANM, that 20171117 does contain fixes already, for some CPUs.

Will I even need to care about the microcode, if an upcoming kernel addresses Meltdown/Spectre in other ways?

Sure.
The MELTDOWN vulnerability is a “bug” in the CPUs themselves, and can only be fixed wih a firmware update AIUI. (although part of the fix is in the kernel)

How are you dealing with the vulnerability on your systems?

Not at all.
Except for installing available updates as usual. :wink:

Thanks for the response, Wolf. In that case, it sounds like I should keep an eye out for new snapshots, run zypper dup as usual, and take no other measures.

One less worry!

At the moment,
Based on varied reports it’s likely that patches will be replaced as time goes one due to many reasons, among them that we’re discovering that designs and implementations haven’t always been exactly as publicized, and the installed features of the many CPUs affected. In fact, because of some of these heretofore unknown inconsistencies, some systems have been crashing… And this is without regard of the running OS.

Some openSUSE Forum discussions on this topic, current up to a few days ago so probably very little change as of this post

https://forums.opensuse.org/showthread.php/528882-Serious-Intel-CPU-flaw-patch-coming-Expect-major-system-slowdowns-maybe-noticeable
https://forums.opensuse.org/showthread.php/528914-Notice-and-thinkin-R-Brown

The second link is to a thread that points to a script that evaluates your system’s exposure and vulnerability, both software and hardware.
Because it’s likely that there will be new patches and patches replaced, you will likely want to run the script multiple times for he forseeable future to regularly check your current status.

IMO,
TSU

Sorry, that’s wrong. Meltdown is avoided (not really fixed) in software by hiding kernel address space from user programs. Microcode updates are not related to Meltdown, but are used by one of mitigation techniques for one Spectre variant - disabling branch prediction across critical code. This requires new microcode that implements support for new instructions (and CPU features).

The use of that evaluation script received rather short shrift on bugzilla: 1068032 – (CVE-2017-5715) VUL-0: CVE-2017-5715: speculative side channel attacks on various CPU platforms aka "SpectreAttack" and "MeltdownAttack" :\

Yeah, that’s what I was thinking of actually.
Seems I confused the two…

Is why in my post I described what I saw the script doing… at the time I posted, the script did not run PoC.

BUT,
I don’t agree with the evaluation that such scripts give people a false sense of security.
At the time I posted, the script does plenty while depending on the the work of people we already trust… The openSUSE and kernel maintainers and possibly other trusted contributors. It’s not much different than any other code we trust when running openSUSE.

And,
As I pointed out in that second thread,
By the time I posted again only a couple days later, the script had changed substantially to reflect evolving input to the author of the script.

Bottom line,
The script is not meant to be a PoC of any vulnerability, and even today I would consider even a PoC possibly suspect depending on how it’s written because these vulnerabilities might be susceptible to other vectors than are tested (eg published Javascript Spectre PoC, but what about other languages and vector, eg pipes instead of networking?)

IMO even today it’s possibly too early to understand the scope of possible attack vectors and this is important when current Spectre patches appear to try to block only the attack vector when we don’t yet know how to fix the source of the problem.

As ordinary Users (assuming my audience doesn’t include people actually trying to write code), IMO a scanning tool like the script can serve a useful purpose, to know if you’re protected as best as possible at that moment (but, keep checking until some announcement that the vulnerabilities are fixed once and for all).

IMO,
TSU

So what is happening about openSUSE Tumbleweed and these vulnerabilities ?

because CPUINFO still claim it is there

bugs : cpu_meltdown spectre_v1 spectre_v2 spec_store_bypass
bogomips : 6384.00
clflush size : 64
cache_alignment : 64
address sizes : 39 bits physical, 48 bits virtual
power management:

uname -a
Linux ra 4.17.5-1-default #1 SMP PREEMPT Mon Jul 9 07:29:02 UTC 2018 (3ff6a16) x86_64 x86_64 x86_64 GNU/Linux

what does
cat /sys/devices/system/cpu/vulnerabilities/*
say?

Have your replaced your CPU with another model where these vulnerabilities are fixed? If not, why do you expect them to magically disappear?

There is something like this? I want one too. :wink:
P.S. Fixed - hardware not software.

Not that I’m aware of. Note that it only can fix Meltdown; Spectre vulnerabilites are very unlikely to be fixed in hardware, at least without total redesign.

As about a month ago when I researched the state of what Intel CPUs were affected (I didn’t check any other CPU including AMD),

Any Intel CPU shipped from factory with a date stamp 2017 or later can be patched.
But, only CPUs shipped after Feb/Mar 2018 likely shipped with a patch applied.

It was unclear to me whether firmware patches to address Meltdown/Spectre could be applied through an OS update or if a firmware upgrade had to be performed. In any case, as I opined in an earlier post in this thread updated patches have been released regularly to block attack vectors.

TSU

Off-topic.

Not only the firmware patches have an impact on performance.
It seems that the browser(s) will have an impact, too.
https://security.googleblog.com/2018/07/mitigating-spectre-with-site-isolation.html
I hope that the Spectre issue will have an “silicon” fix soon.

There is no performance impact of microcode updates per se. Do you have numbers that prove performance drop using one year old kernel (i.e. kernel without patches)?

I hope that the Spectre issue will have an “silicon” fix soon.

Fixing known Spectre vulnerabilities is easy - just remove speculative execution and pipelines. I doubt you will like the result.

What you apparently miss is that Spectre simply demonstrates that virtually anything that CPU does can potentially be abused to guess some information that would normally not be available to attacker. What we have seen were just most low hanging fruits.

Sorry, this is what I understand:
https://access.redhat.com/security/vulnerabilities/speculativeexecution?page=3
I do not have numbers to prove that.

About the “silicon” fixes:
https://www.digitaltrends.com/computing/intel-meltdown-spectre-silicon-fixes-ice-lake/
https://newsroom.intel.com/editorials/advancing-security-silicon-level/
This is what I read. I do not have specialized knowledge in CPU architecture.:frowning:

It talks about combined microcode and kernel update. If course it will have performance impact, nobody disputes it.

https://newsroom.intel.com/editorials/advancing-security-silicon-level/
Even this one says “Variant 1 will continue to be addressed via software mitigations”. Of course it may be possible to design mitigation for known vulnerabilities. But since the first announcement multiple new variations of Spectre have already been discovered (at least made known). This will be never-ending story given current shared nature of CPU. Unless each execution thread can be completely isolated from another, this will continue.