It is currently 25 May 2018, 09:51




 Page 1 of 1 [ 7 posts ] 
Author Message
 Post subject: SPECTRE and MELTDOWN CPU flaws
PostPosted: 09 Jan 2018, 06:33 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 1924
Location: Tg Pagar, Singapore
Has thanked: 43 times
Been thanked: 58 times
Just a quick notice that LDDb server has been rebooted with a fresh Linux Kernel including the mitigation patches again recently published Intel CPU flaws:

http://www.lddb.com/history.php?version=3.1


We're running 4.14.12 now with all patches for Intel turned on.

Hopefully the performance decrease linked with the extra security will not slow everything down too much.

Julien
_________________
Shop on LDDb / Shop on eBay SG / LDDb on Facebook!
Offline
 Profile  
 
 Post subject: Re: SPECTRE and MELTDOWN CPU flaws
PostPosted: 11 Jan 2018, 03:41 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 1924
Location: Tg Pagar, Singapore
Has thanked: 43 times
Been thanked: 58 times
Will keep patching as the fixes become available.

Current status:

Quote:
Spectre and Meltdown mitigation detection tool v0.24

Checking for vulnerabilities against live running kernel Linux 4.14.12 #1 SMP Sun Jan 7 15:41:58 CET 2018 x86_64

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Checking count of LFENCE opcodes in kernel: NO (only 43 opcodes found, should be >= 70)
> STATUS: VULNERABLE (heuristic to be improved when official patches become available)

CVE-2017-5715 [branch target injection] aka 'Spectre Variant 2'
* Mitigation 1
* Hardware (CPU microcode) support for mitigation: NO
* Kernel support for IBRS: NO
* IBRS enabled for Kernel space: NO
* IBRS enabled for User space: NO
* Mitigation 2
* Kernel compiled with retpoline option: NO
* Kernel compiled with a retpoline-aware compiler: NO
> STATUS: VULNERABLE (IBRS hardware + kernel support OR kernel with retpoline are needed to mitigate the vulnerability)

CVE-2017-5754 [rogue data cache load] aka 'Meltdown' aka 'Variant 3'
* Kernel supports Page Table Isolation (PTI): YES
* PTI enabled and active: YES
> STATUS: NOT VULNERABLE (PTI mitigates the vulnerability)


CPU microcode will be updated at the next required reboot, probably for Linux 4.15 imminent release.

Julien
_________________
Shop on LDDb / Shop on eBay SG / LDDb on Facebook!
Offline
 Profile  
 
 Post subject: Re: SPECTRE and MELTDOWN CPU flaws
PostPosted: 13 Jan 2018, 07:30 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 1924
Location: Tg Pagar, Singapore
Has thanked: 43 times
Been thanked: 58 times
Script updated (v0.24 to v0.28)

Quote:
Spectre and Meltdown mitigation detection tool v0.28

Checking for vulnerabilities against running kernel Linux 4.14.12 #1 SMP Sun Jan 7 15:41:58 CET 2018 x86_64
CPU is Intel(R) Xeon(R) CPU E3-1230 v3 @ 3.30GHz

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Checking count of LFENCE opcodes in kernel: NO
> STATUS: VULNERABLE (only 22 opcodes found, should be >= 70, heuristic to be improved when official patches become available)

CVE-2017-5715 [branch target injection] aka 'Spectre Variant 2'
* Mitigation 1
* Hardware (CPU microcode) support for mitigation: NO
* Kernel support for IBRS: NO
* IBRS enabled for Kernel space: NO
* IBRS enabled for User space: NO
* Mitigation 2
* Kernel compiled with retpoline option: NO
* Kernel compiled with a retpoline-aware compiler: NO
> STATUS: VULNERABLE (IBRS hardware + kernel support OR kernel with retpoline are needed to mitigate the vulnerability)

CVE-2017-5754 [rogue data cache load] aka 'Meltdown' aka 'Variant 3'
* Kernel supports Page Table Isolation (PTI): YES
* PTI enabled and active: YES
> STATUS: NOT VULNERABLE (PTI mitigates the vulnerability)

Julien
_________________
Shop on LDDb / Shop on eBay SG / LDDb on Facebook!
Offline
 Profile  
 
 Post subject: Re: SPECTRE and MELTDOWN CPU flaws
PostPosted: 14 Jan 2018, 10:06 
Absolute fan
Absolute fan
User avatar

Joined: 02 May 2006, 13:59
Posts: 1590
Location: United Kingdom
Has thanked: 21 times
Been thanked: 13 times
Good day Julien,

I have been ready about the Intel Chip flaws with some concern.

Thank you for your professional reassurances as always Friend,

Apart from the above how is life and are you doing well personally and with your businesses.

Sincerest Regards

Mark
_________________
Το ταξίδι για την αλήθεια κάθε σκάφος δεμένα, κατόπιν δεν είναι να ληφθούν, ή μάλλον βάδισαν
Offline
 Profile  
 
 Post subject: Re: SPECTRE and MELTDOWN CPU flaws
PostPosted: 15 Jan 2018, 13:06 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 1924
Location: Tg Pagar, Singapore
Has thanked: 43 times
Been thanked: 58 times
Script updated (v0.28 to v0.31)

Quote:
Spectre and Meltdown mitigation detection tool v0.31

Checking for vulnerabilities against running kernel Linux 4.14.12 #1 SMP Sun Jan 7 15:41:58 CET 2018 x86_64
CPU is Intel(R) Xeon(R) CPU E3-1230 v3 @ 3.30GHz

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Checking count of LFENCE opcodes in kernel: NO
> STATUS: VULNERABLE (only 22 opcodes found, should be >= 70, heuristic to be improved when official patches become available)

CVE-2017-5715 [branch target injection] aka 'Spectre Variant 2'
* Mitigation 1
* Hardware (CPU microcode) support for mitigation
* The SPEC_CTRL MSR is available: NO
* The SPEC_CTRL CPUID feature bit is set: NO
* Kernel support for IBRS: NO
* IBRS enabled for Kernel space: NO
* IBRS enabled for User space: NO
* Mitigation 2
* Kernel compiled with retpoline option: NO
* Kernel compiled with a retpoline-aware compiler: NO
> STATUS: VULNERABLE (IBRS hardware + kernel support OR kernel with retpoline are needed to mitigate the vulnerability)

CVE-2017-5754 [rogue data cache load] aka 'Meltdown' aka 'Variant 3'
* Kernel supports Page Table Isolation (PTI): YES
* PTI enabled and active: YES
* Checking if we're running under Xen PV (64 bits): NO
> STATUS: NOT VULNERABLE (PTI mitigates the vulnerability)

Julien
_________________
Shop on LDDb / Shop on eBay SG / LDDb on Facebook!
Offline
 Profile  
 
 Post subject: Re: SPECTRE and MELTDOWN CPU flaws
PostPosted: 29 Jan 2018, 10:26 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 1924
Location: Tg Pagar, Singapore
Has thanked: 43 times
Been thanked: 58 times
admin wrote:
CPU microcode will be updated at the next required reboot, probably for Linux 4.15 imminent release.


Linux Kernel 4.15 was released today: http://www.zdnet.com/article/linux-4-15-good-news-and-bad-news-about-meltdown-and-spectre/

Will schedule a server reboot as soon as practical.

Script updated (v0.31 to v0.33)

Quote:
Spectre and Meltdown mitigation detection tool v0.33

Checking for vulnerabilities on current system
Kernel is Linux 4.14.12 #1 SMP Sun Jan 7 15:41:58 CET 2018 x86_64
CPU is Intel(R) Xeon(R) CPU E3-1230 v3 @ 3.30GHz

Hardware check
* Hardware support (CPU microcode) for mitigation techniques
* Indirect Branch Restricted Speculation (IBRS)
* SPEC_CTRL MSR is available: NO
* CPU indicates IBRS capability: NO
* Indirect Branch Prediction Barrier (IBPB)
* PRED_CMD MSR is available: NO
* CPU indicates IBPB capability: NO
* Single Thread Indirect Branch Predictors (STIBP)
* SPEC_CTRL MSR is available: NO
* CPU indicates STIBP capability: NO
* Enhanced IBRS (IBRS_ALL)
* CPU indicates ARCH_CAPABILITIES MSR availability: NO
* ARCH_CAPABILITIES MSR advertises IBRS_ALL capability: NO
* CPU explicitly indicates not being vulnerable to Meltdown (RDCL_NO): NO
* CPU microcode is known to cause stability problems: NO
* CPU vulnerability to the three speculative execution attacks variants
* Vulnerable to Variant 1: YES
* Vulnerable to Variant 2: YES
* Vulnerable to Variant 3: YES

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Checking count of LFENCE opcodes in kernel: NO
> STATUS: VULNERABLE (only 22 opcodes found, should be >= 70, heuristic to be improved when official patches become available)

CVE-2017-5715 [branch target injection] aka 'Spectre Variant 2'
* Mitigation 1
* Kernel is compiled with IBRS/IBPB support: NO
* Currently enabled features
* IBRS enabled for Kernel space: NO
* IBRS enabled for User space: NO
* IBPB enabled: NO
* Mitigation 2
* Kernel compiled with retpoline option: NO
* Kernel compiled with a retpoline-aware compiler: NO
* Retpoline enabled: NO
> STATUS: VULNERABLE (IBRS hardware + kernel support OR kernel with retpoline are needed to mitigate the vulnerability)

CVE-2017-5754 [rogue data cache load] aka 'Meltdown' aka 'Variant 3'
* Kernel supports Page Table Isolation (PTI): YES
* PTI enabled and active: YES
* Checking if we're running under Xen PV (64 bits): NO
> STATUS: NOT VULNERABLE (PTI mitigates the vulnerability)


Julien
_________________
Shop on LDDb / Shop on eBay SG / LDDb on Facebook!
Offline
 Profile  
 
 Post subject: Re: SPECTRE and MELTDOWN CPU flaws
PostPosted: 30 Jan 2018, 07:52 
Site Admin
Site Admin
User avatar

Joined: 07 Aug 2002, 23:37
Posts: 1924
Location: Tg Pagar, Singapore
Has thanked: 43 times
Been thanked: 58 times
Just rebooted with Kernel 4.15.

Baby steps...

Quote:
Spectre and Meltdown mitigation detection tool v0.33+

Checking for vulnerabilities on current system
Kernel is Linux 4.15.0 #1 SMP Mon Jan 29 05:15:04 CET 2018 x86_64
CPU is Intel(R) Xeon(R) CPU E3-1230 v3 @ 3.30GHz

Hardware check
* Hardware support (CPU microcode) for mitigation techniques
* Indirect Branch Restricted Speculation (IBRS)
* SPEC_CTRL MSR is available: NO
* CPU indicates IBRS capability: NO
* Indirect Branch Prediction Barrier (IBPB)
* PRED_CMD MSR is available: NO
* CPU indicates IBPB capability: NO
* Single Thread Indirect Branch Predictors (STIBP)
* SPEC_CTRL MSR is available: NO
* CPU indicates STIBP capability: NO
* Enhanced IBRS (IBRS_ALL)
* CPU indicates ARCH_CAPABILITIES MSR availability: NO
* ARCH_CAPABILITIES MSR advertises IBRS_ALL capability: NO
* CPU explicitly indicates not being vulnerable to Meltdown (RDCL_NO): NO
* CPU microcode is known to cause stability problems: NO
* CPU vulnerability to the three speculative execution attacks variants
* Vulnerable to Variant 1: YES
* Vulnerable to Variant 2: YES
* Vulnerable to Variant 3: YES

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Mitigated according to the /sys interface: NO (kernel confirms your system is vulnerable)
> STATUS: VULNERABLE (Vulnerable)

CVE-2017-5715 [branch target injection] aka 'Spectre Variant 2'
* Mitigation 1
* Kernel is compiled with IBRS/IBPB support: NO
* Currently enabled features
* IBRS enabled for Kernel space: NO
* IBRS enabled for User space: NO
* IBPB enabled: NO
* Mitigation 2
* Kernel compiled with retpoline option: YES
* Kernel compiled with a retpoline-aware compiler: NO (kernel reports minimal retpoline compilation)
* Retpoline enabled: YES
> STATUS: VULNERABLE (Vulnerable: Minimal generic ASM retpoline)

CVE-2017-5754 [rogue data cache load] aka 'Meltdown' aka 'Variant 3'
* Mitigated according to the /sys interface: YES (kernel confirms that the mitigation is active)
* Kernel supports Page Table Isolation (PTI): YES
* PTI enabled and active: YES
* Running as a Xen PV DomU: NO
> STATUS: NOT VULNERABLE (Mitigation: PTI)


Julien
_________________
Shop on LDDb / Shop on eBay SG / LDDb on Facebook!
Offline
 Profile  
 
Display posts from previous:  Sort by  
 Page 1 of 1 [ 7 posts ] 


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to: