Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #62436

Bug#912109: Spectre Meltdown. System has more than MAX_PA/2 memory. L1TF mitigation not effective for CVE-2018-3620

Path csiph.com!news.mixmin.net!news.unit0.net!newsfeed.CARNet.hr!news.spin.it!bofh.it!news.nic.it!robomod
From <bugs@appelo.org>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#912109: Spectre Meltdown. System has more than MAX_PA/2 memory. L1TF mitigation not effective for CVE-2018-3620
Date Sun, 28 Oct 2018 13:10:01 +0100
Message-ID <wNS3f-5GS-5@gated-at.bofh.it> (permalink)
References <wNQNQ-4MX-11@gated-at.bofh.it>
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Sun Oct 28 12:06:11 2018
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -3.941
Reply-To <bugs@appelo.org>, 912109@bugs.debian.org
Original-Sender "tobias appelo" <tobias@appelo.org>
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc Debian Kernel Team <debian-kernel@lists.debian.org>
X-Debian-Pr-Message followup 912109
X-Debian-Pr-Package src:linux
X-Debian-Pr-Keywords security
X-Debian-Pr-Source linux
X-Spam-Bayes score:0.0000 Tokens: new, 56; hammy, 146; neutral, 247; spammy, 4. spammytokens:0.999-+--H*x:Outlook, 0.999-+--H*UA:Outlook, 0.998-+--H*x:Microsoft, 0.998-+--H*UA:Microsoft hammytokens:0.000-+--UD:kernel.org, 0.000-+--UD:git.kernel.org, 0.000-+--gitkernelorg, 0.000-+--git.kernel.org, 0.000-+--6.3.0-18
Sender robomod@news.nic.it
MIME-Version 1.0
Content-Type text/plain; charset="iso-8859-1"
Content-Transfer-Encoding quoted-printable
X-Mailer Microsoft Outlook 15.0
Thread-Index AdRusmNapzcFKhtMSCKGkQs/Rbxzqw==
Content-Language en-us
X-Sourceip 62.194.123.84
X-Authenticated-Sender tobiasappelo@ziggo.nl (via SMTP)
X-Ziggo-Spambar /
X-Ziggo-Spamscore 0.0
X-Ziggo-Spamreport CMAE Analysis: v=2.3 cv=LaOIFQXi c=1 sm=1 tr=0 a=auX/KeoFmZsfskQIefXk4g==:17 a=9+rZDBEiDlHhcck0kWbJtElFXBc=:19 a=8nJEP1OIZ-IA:10 a=smKx5t2vBNcA:10 a=SNTq-XoPAAAA:8 a=danhDmx_AAAA:8 a=VwQbUJbxAAAA:8 a=FW5SSaDIAAAA:8 a=NEAV23lmAAAA:8 a=KSb9T-wMAAAA:8 a=xNf9USuDAAAA:8 a=MuQWIMa8zRYzh1OX5QsA:9 a=wPNLvfGTeEIA:10 a=NDmDBtyS5Z9D6f_M-ZS5:22 a=P4VdviVPEcjfz_PVVggX:22 a=AjGcO6oz07-iQ99wixmX:22 a=8hRcP3ObCMEPUD2Q1f5I:22 a=KF4VuIdXkMyp4E_ug72i:22 a=SEwjQc04WA-l_NiBhQ7s:22
X-Ziggo-Spam-Status No
X-Greylist delayed 1321 seconds by postgrey-1.36 at buxtehude; Sun, 28 Oct 2018 12:04:37 UTC
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1494399
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 129
Organization linux.* mail to news gateway
X-Original-Date Sun, 28 Oct 2018 12:41:57 +0100
X-Original-Message-ID <013701d46eb3$3b9a3430$b2ce9c90$@appelo.org>
X-Original-References <154072022604.14640.12427958198767572775.reportbug@serafijn.appelo.org>
X-Original-Sender "tobias appelo" <tobias@appelo.org>
Xref csiph.com linux.debian.bugs.dist:924754 linux.debian.kernel:62436

Cross-posted to 2 groups.

Show key headers only | View raw


Hi,

Thx for responding quickly.
I have the microcode package installed.

dpkg -l | grep microcode
ii  intel-microcode                3.20180807a.1~deb9u1           amd64
Processor microcode firmware for Intel
and activated:
# dmesg | grep microc
[    0.000000] microcode: microcode updated early to revision 0x20, date =
2018-04-10
[    0.545764] microcode: sig=0x306a9, pf=0x2, revision=0x20
[    0.545879] microcode: Microcode Update Driver: v2.01
<tigran@aivazian.fsnet.co.uk>, Peter Oruba

From what i read the issue applies to certain ram / cpu combo's.
Not sure if it's reproducible @ azure.

There is some more about it as well:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1788563

and here the upstream fix:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?i
d=b0a182f875689647b014bc01d36b340217792852

regards,

Tobias.


On Sun, 28 Oct 2018 10:50:26 +0100 tobias <bugs@appelo.org> wrote:
> Package: src:linux
> Version: 4.9.110-3+deb9u6
> Severity: normal
> Tags: security
> 
> According to
https://github.com/speed47/spectre-meltdown-checker/releases/tag/v0.40 my
system is vulnerable for vulnerability CVE-2018-3620 
> 
> results:
> 
> CVE-2018-3620 aka 'Foreshadow-NG (OS), L1 terminal fault'
> * Mitigated according to the /sys interface:  NO  (Vulnerable)
> * Kernel supports PTE inversion:  YES  (found in kernel image)
> * PTE inversion enabled and active:  NO
> STATUS:  VULNERABLE  (Vulnerable)
> 
> 
>  dmesg | grep L1TF
>  [    0.014828] L1TF: System has more than MAX_PA/2 memory. L1TF
>  mitigation not effective.
> 
> workaround:
> as described here: https://bugzilla.opensuse.org/show_bug.cgi?id=1105536
> supplied command line parameter "mem=33554428k" and the issue is gone.
> 
> 
> 
> -- Package-specific info:
> ** Version:
> Linux version 4.9.0-8-amd64 (debian-kernel@lists.debian.org) (gcc version
6.3.0 20170516 (Debian 6.3.0-18+deb9u1) ) #1 SMP Debian 4.9.110-3+deb9u6
(2018-10-08)
> 
> ** Command line:
> BOOT_IMAGE=/boot/vmlinuz-4.9.0-8-amd64 root=/dev/mapper/vol00-lvroot ro
ipv6.disable=1 quiet
> 
> ** Not tainted
> 
> ** Kernel log:
> [   22.581813] device veth5bacacd entered promiscuous mode
> [   22.581854] br-f6f67b537c3b: port 1(veth5bacacd) entered blocking state
> [   22.581855] br-f6f67b537c3b: port 1(veth5bacacd) entered forwarding
state
> [   22.581935] br-f6f67b537c3b: port 1(veth5bacacd) entered disabled state
> [   22.587449] br-ced3a9da9295: port 1(veth1f742ed) entered blocking state
> [   22.587450] br-ced3a9da9295: port 1(veth1f742ed) entered disabled state
> [   22.587483] device veth1f742ed entered promiscuous mode
> [   22.587522] br-ced3a9da9295: port 1(veth1f742ed) entered blocking state
> [   22.587523] br-ced3a9da9295: port 1(veth1f742ed) entered forwarding
state
> [   22.587564] br-ced3a9da9295: port 1(veth1f742ed) entered disabled state
> [   22.696461] br-429b9edca99c: port 1(veth8d7b672) entered blocking state
> [   22.696463] br-429b9edca99c: port 1(veth8d7b672) entered disabled state
> [   22.696495] device veth8d7b672 entered promiscuous mode
> [   22.696533] br-429b9edca99c: port 1(veth8d7b672) entered blocking state
> [   22.696534] br-429b9edca99c: port 1(veth8d7b672) entered forwarding
state
> [   22.696568] br-429b9edca99c: port 1(veth8d7b672) entered disabled state
> [   22.717457] br-f6f67b537c3b: port 2(veth423bb83) entered blocking state
> [   22.717458] br-f6f67b537c3b: port 2(veth423bb83) entered disabled state
> [   22.717488] device veth423bb83 entered promiscuous mode
> [   22.717772] br-eb3952fed7f5: port 1(vethe2fd06e) entered blocking state
> [   22.717773] br-eb3952fed7f5: port 1(vethe2fd06e) entered disabled state
> [   22.717801] device vethe2fd06e entered promiscuous mode
> [   22.717835] br-eb3952fed7f5: port 1(vethe2fd06e) entered blocking state
> [   22.717836] br-eb3952fed7f5: port 1(vethe2fd06e) entered forwarding
state

Back to linux.debian.kernel | Previous | Next | Find similar | Unroll thread


Thread

Bug#912109: Spectre Meltdown. System has more than MAX_PA/2 memory. L1TF mitigation not effective for CVE-2018-3620 <bugs@appelo.org> - 2018-10-28 13:10 +0100

csiph-web