Skip to main content

Massive Vulnerability Resulting In Meltdown and Specter Attacks

I planned to update Arch every 10 days but since updating some 3 days ago, news of a massive vulnerability in the chip processor all computers use came out. There are two demonstrated attacks called Meltdown and Specter. So let me use the language of the OpenSuse security patch email here to explain what these are.


CVE-2017-5753 / "SpecŧreAttack": Local attackers on systems with modern

     CPUs featuring deep instruction pipelining could use attacker
     controllable speculative execution over code patterns in the Linux
     Kernel to leak content from otherwise not readable memory in the same
     address space, allowing retrieval of passwords, cryptographic keys and
     other secrets.

     This problem is mitigated by adding speculative fencing on affected code
   paths throughout the Linux kernel.


   - CVE-2017-5715 / "SpectreAttack": Local attackers on systems with modern
     CPUs featuring branch prediction could use mispredicted branches to
     speculatively execute code patterns that in turn could be made to leak
     other non-readable content in the same address space, an attack similar
     to CVE-2017-5753.

     This problem is mitigated by disabling predictive branches, depending
     on CPU architecture either by firmware updates and/or fixes in the
      user-kernel privilege boundaries.

     Please also check with your CPU / Hardware vendor on updated firmware
     or BIOS images regarding this issue.

     As this feature can have a performance impact, it can be disabled using
   the "nospec" kernel commandline option.


   - CVE-2017-5754 / "MeltdownAttack": Local attackers on systems with modern
     CPUs featuring deep instruction pipelining could use code patterns in
     userspace to speculative executive code that would read
     otherwise read protected memory, an attack similar to CVE-2017-5753.

     This problem is mitigated by unmapping the Linux Kernel from the user
   address space during user code execution, following a approach called
   "KAISER". The terms used here are "KAISER" / "Kernel Address Isolation"
   and "PTI" / "Page Table Isolation".

     Note that this is only done on affected platforms.

     This feature can be enabled / disabled by the "pti=[on|off|auto]" or
   "nopti" commandline options.

Linux distros have pushed patches so I'm doing an update today. I'm updating my mirrors first with.

$ reflector --latest 8 --protocol https --sort rate --save /etc/pacman.d/mirrorlist

Then I update my system with --

$ pacman -Syu

I should be receiving the same patch that OpenSuse pushed to their users.

Comments

Popular posts from this blog

Appindicator In Natty Ubuntu 11.04

Previously ranted about the blind alley Ubuntu 11.04 seemed to be leading us when it comes to some applications not being ready yet for the dropping of system tray.  What I should have done is press on. There are posts about editing a white list with a recommended GUI tool to help us out here , here and here . Like everything in Linux, there's a configuration file for it, if you can find it and if you have the inclination to go ninja. If not then there's dconf-editor. Download dconf-tools from Software Center. Navigate to desktop>unity>panel. Add your application in the white list. Then close the window. No save button. mmm. So far I have added Shutter, Dropbox and Keepassx in the white list.                Before...  After.

Evolution Mail on GNOME 3.26

There's a slight change in the user interface. A To Do column now appears to the rightmost after the GNOME 3.26 update. Also there's a noticeable stability increase, what with goa-daemon stopping its RAM usage creep. I don't have to kill it every couple of hours.

New Converge ICT Plan Max with Sky Now

I pulled the trigger on Converge Max plan 400Mbps with Sky channels. I went to their sales office and asked for the upgrade. No charge at all and they didn't ask me to return the old modem. It looks like they will pull it when they install the new modem.e     It came with a black box for the TV. The configuration is easy but it took me 3 days to figure out the Wired connection. It should be fine except I have to jiggle it in the config (GUI). Turn 802.1x  on and off to finally connect.  Here's the speed for the Wired connection: