Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #59818 > unrolled thread

Re: Intel Vulnerability

Started byYves-Alexis Perez <corsac@debian.org>
First post2018-01-04 22:30 +0100
Last post2018-01-05 08:40 +0100
Articles 7 — 4 participants

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: Intel Vulnerability Yves-Alexis Perez <corsac@debian.org> - 2018-01-04 22:30 +0100
    Re: Intel Vulnerability Yves-Alexis Perez <corsac@debian.org> - 2018-01-05 08:20 +0100
      Re: Intel Vulnerability Ozgur <ozgur@goosey.org> - 2018-01-05 08:50 +0100
        Re: Intel Vulnerability maximilian attems <maks@stro.at> - 2018-01-05 09:30 +0100
          Re: Intel Vulnerability Ozgur <ozgur@goosey.org> - 2018-01-05 09:40 +0100
        Re: Intel Vulnerability "Torben Schou Jensen" <tsj@swampthing.dk> - 2018-01-05 09:30 +0100
    Re: Intel Vulnerability Ozgur <ozgur@goosey.org> - 2018-01-05 08:40 +0100

#59818 — Re: Intel Vulnerability

FromYves-Alexis Perez <corsac@debian.org>
Date2018-01-04 22:30 +0100
SubjectRe: Intel Vulnerability
Message-ID<v4lfj-2H8-9@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

On Thu, 2018-01-04 at 20:51 +0000, Joe.Ghalam@dell.com wrote:
> Does anyone have any information about plans for releasing patches for the
> Intel vulnerability issues for Debian Jessie and/or Stretch? Any information
> would be really appreciated.

Hi Joe,

we are currently in the process of releasing updates addressing CVE-2017-5754
(meltdown) for Stretch.

Jessie will follow later, as well as fixes for Spectre if/when they are
available.

Regards,
-- 
Yves-Alexis

[toc] | [next] | [standalone]


#59824

FromYves-Alexis Perez <corsac@debian.org>
Date2018-01-05 08:20 +0100
Message-ID<v4ush-v8-3@gated-at.bofh.it>
In reply to#59818

[Multipart message — attachments visible in raw view] — view raw

On Fri, 2018-01-05 at 10:07 +0300, Ozgur wrote:
> I talked yesterday Debian kernel team and was a work on Debian kernel for
> the latest stable, I think all users add to "x86_64_BUG_CPU_INSECURE"
> parameter .config file and add "= y" added and recompiled.

Hi Ozgur,

that's completely irrelevant. For Meltdown fix on Stretch/amd64, please
upgrade to the just published linux-image-4.9.0-5-amd64 version 4.9.65-3+deb9u2.

Regards,
-- 
Yves-Alexis

[toc] | [prev] | [next] | [standalone]


#59828

FromOzgur <ozgur@goosey.org>
Date2018-01-05 08:50 +0100
Message-ID<v4uVj-FD-1@gated-at.bofh.it>
In reply to#59824

05.01.2018, 10:16, "Yves-Alexis Perez" <corsac@debian.org>:
> On Fri, 2018-01-05 at 10:07 +0300, Ozgur wrote:
>>  I talked yesterday Debian kernel team and was a work on Debian kernel for
>>  the latest stable, I think all users add to "x86_64_BUG_CPU_INSECURE"
>>  parameter .config file and add "= y" added and recompiled.
>
> Hi Ozgur,

Hello Alexis,

thanks for reply and I'm using the stable version (Debian stretch). I updated last night and I don't seen any new kernel patch yet.

sources.list:

deb http://security.debian.org/debian-security stretch/updates main contrib non-free
deb-src http://security.debian.org/debian-security stretch/updates main contrib non-free

deb http://deb.debian.org/debian/ stretch-updates main contrib non-free
deb-src http://deb.debian.org/debian/ stretch-updates main contrib non-free

deb http://deb.debian.org/debian/ stretch main contrib non-free
deb-src http://deb.debian.org/debian/ stretch main contrib non-free

$ uname -ar
Linux laptop.debian.local 4.9.0-5-amd64 #1 SMP Debian 4.9.65-3+deb9u2 (2018-01-04) x86_64 GNU/Linux

Regards

Ozgur

> that's completely irrelevant. For Meltdown fix on Stretch/amd64, please
> upgrade to the just published linux-image-4.9.0-5-amd64 version 4.9.65-3+deb9u2.
>
> Regards,
> --
> Yves-Alexis

[toc] | [prev] | [next] | [standalone]


#59829

Frommaximilian attems <maks@stro.at>
Date2018-01-05 09:30 +0100
Message-ID<v4vy1-18H-3@gated-at.bofh.it>
In reply to#59828
Dear Ozgur,

On Fri, Jan 05, 2018 at 10:29:56AM +0300, Ozgur wrote:
> 
> thanks for reply and I'm using the stable version (Debian stretch). I updated last night and I don't seen any new kernel patch yet.
> 

Please use a user list for your support, this mailing list is for development purpose.

thank you,

-- 
maks

[toc] | [prev] | [next] | [standalone]


#59831

FromOzgur <ozgur@goosey.org>
Date2018-01-05 09:40 +0100
Message-ID<v4vHI-1ce-9@gated-at.bofh.it>
In reply to#59829

05.01.2018, 10:56, "maximilian attems" <maks@stro.at>:
> Dear Ozgur,

Hello Max,

> On Fri, Jan 05, 2018 at 10:29:56AM +0300, Ozgur wrote:
>>  thanks for reply and I'm using the stable version (Debian stretch). I updated last night and I don't seen any new kernel patch yet.
>
> Please use a user list for your support, this mailing list is for development purpose.
>
> thank you,

okay, thank you.

> --
> maks

Regards,

Ozgur

[toc] | [prev] | [next] | [standalone]


#59830

From"Torben Schou Jensen" <tsj@swampthing.dk>
Date2018-01-05 09:30 +0100
Message-ID<v4vy1-18H-1@gated-at.bofh.it>
In reply to#59828
Ok, so x86_64_BUG_CPU_INSECURE will be optional in kernel config.

As I read Meltdown is primary a security risk on server farms where
multiple customers use same CPU.

If I have my own private server on own hardware, and thereby have full
control over software in use, then I might get a performance boost by not
using x86_64_BUG_CPU_INSECURE and thereby use full standard speculative
execution.

Brgds
Torben

[toc] | [prev] | [next] | [standalone]


#59826

FromOzgur <ozgur@goosey.org>
Date2018-01-05 08:40 +0100
Message-ID<v4ush-v8-5@gated-at.bofh.it>
In reply to#59818

05.01.2018, 00:23, "Yves-Alexis Perez" <corsac@debian.org>:
> On Thu, 2018-01-04 at 20:51 +0000, Joe.Ghalam@dell.com wrote:
>>  Does anyone have any information about plans for releasing patches for the
>>  Intel vulnerability issues for Debian Jessie and/or Stretch? Any information
>>  would be really appreciated.
>
> Hi Joe,
>
> we are currently in the process of releasing updates addressing CVE-2017-5754
> (meltdown) for Stretch.

Hello,

I talked yesterday Debian kernel team and was a work on Debian kernel for the latest stable, I think all users add to "x86_64_BUG_CPU_INSECURE" parameter .config file and add "= y" added and recompiled.

Regards

Ozgur

> Jessie will follow later, as well as fixes for Spectre if/when they are
> available.
>
> Regards,
> --
> Yves-Alexis

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web