Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #192657 > unrolled thread

Is Debian Linux protected against the Meltdown and Spectre security flaws?

Started byTurritopsis Dohrnii Teo En Ming <tdteoenming@gmail.com>
First post2018-02-19 14:20 +0100
Last post2018-02-27 17:10 +0100
Articles 20 on this page of 29 — 11 participants

Back to article view | Back to linux.debian.user


Contents

  Is Debian Linux protected against the Meltdown and Spectre security flaws? Turritopsis Dohrnii Teo En Ming <tdteoenming@gmail.com> - 2018-02-19 14:20 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 14:40 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Roberto C. Sánchez <roberto@debian.org> - 2018-02-19 15:30 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 06:00 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-20 14:50 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-19 15:20 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 18:00 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Reco <recoverym4n@gmail.com> - 2018-02-19 18:10 +0100
          Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 18:50 +0100
            Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Reco <recoverym4n@gmail.com> - 2018-02-19 19:10 +0100
              Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:40 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:30 +0100
          Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 20:10 +0100
            Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 20:20 +0100
              Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 22:30 +0100
                Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 06:10 +0100
                  Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-20 09:30 +0100
                    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-20 11:10 +0100
                      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-20 16:00 +0100
                  Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-02-20 10:20 +0100
                    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 16:20 +0100
    Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Brad Rogers <brad@fineby.me.uk> - 2018-02-19 15:20 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:40 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Brad Rogers <brad@fineby.me.uk> - 2018-02-19 20:20 +0100
        Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Gene Heskett <gheskett@shentel.net> - 2018-02-19 21:30 +0100
          Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-19 21:50 +0100
            Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-20 00:20 +0100
            Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Gene Heskett <gheskett@shentel.net> - 2018-02-20 00:30 +0100
      Re: Is Debian Linux protected against the Meltdown and Spectre  security flaws? Vincent Lefevre <vincent@vinc17.net> - 2018-02-27 17:10 +0100

Page 1 of 2  [1] 2  Next page →


#192657 — Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromTurritopsis Dohrnii Teo En Ming <tdteoenming@gmail.com>
Date2018-02-19 14:20 +0100
SubjectIs Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkTwm-3uw-7@gated-at.bofh.it>
What are the patches that I can download and install to be protected
against the Meltdown and Spectre security vulnerabilities?

===BEGIN SIGNATURE===

Turritopsis Dohrnii Teo En Ming's Academic Qualifications as at 30 Oct 2017

[1] https://tdtemcerts.wordpress.com/

[2] http://tdtemcerts.blogspot.sg/

[3] https://www.scribd.com/user/270125049/Teo-En-Ming

===END SIGNATURE===

[toc] | [next] | [standalone]


#192663 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-02-19 14:40 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkTPH-3AI-5@gated-at.bofh.it>
In reply to#192657

[Multipart message — attachments visible in raw view] — view raw

On 19 February 2018 at 13:13, Turritopsis Dohrnii Teo En Ming <
tdteoenming@gmail.com> wrote:

> What are the patches that I can download and install to be protected
> against the Meltdown and Spectre security vulnerabilities?
>
> ===BEGIN SIGNATURE===
>
> Turritopsis Dohrnii Teo En Ming's Academic Qualifications as at 30 Oct 2017
>
> [1] https://tdtemcerts.wordpress.com/
>
> [2] http://tdtemcerts.blogspot.sg/
>
> [3] https://www.scribd.com/user/270125049/Teo-En-Ming
>
> ===END SIGNATURE===
>


​Checkout the debian backports suite (kindly resourcefully suggested by
Andy Smith)

Easiest thing to do when requiring a newer kernel would be to check
the backports suite, so in this case in stretch-backports we find
linux-image-amd64:

    <https://packages.debian.org/stretch-backports/linux-image-amd64>

That's a virtual package that gets you the latest real kernel
package available in that suite, which right now is
linux-image-4.14.0-0.bpo.3-amd64:

    <https://packages.debian.org/stretch-backports/linux-image-amd64>

>From there, if you look on the right you will see the Debian
changelog link
<http://ftp-master.metadata.debian.org/changelogs//main/l/
linux/linux_4.14.13-1~bpo9+1_changelog>
which tells us that this corresponds to upstream release 4.14.13.
The upstream release was made on 10 January and this backports
package came on 14 January, so that's pretty swift.

Newer kernels should be there now and there may well be one that deals with
both the meltdown and spectre vaulbnerabilities jointly.

Regards

Michael Fothergill

[toc] | [prev] | [next] | [standalone]


#192672 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromRoberto C. Sánchez <roberto@debian.org>
Date2018-02-19 15:30 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkUC5-46d-13@gated-at.bofh.it>
In reply to#192663
On Mon, Feb 19, 2018 at 01:23:25PM +0000, Michael Fothergill wrote:
> 
>    ​Checkout the debian backports suite (kindly resourcefully suggested by
>    Andy Smith)
>    Easiest thing to do when requiring a newer kernel would be to check
>    the backports suite, so in this case in stretch-backports we find
>    linux-image-amd64:
> 
>        <[5]https://packages.debian.org/stretch-backports/linux-image-amd64>
> 
>    That's a virtual package that gets you the latest real kernel
>    package available in that suite, which right now is
>    linux-image-4.14.0-0.bpo.3-amd64:
> 
>        <[6]https://packages.debian.org/stretch-backports/linux-image-amd64>
> 
>    >From there, if you look on the right you will see the Debian
>    changelog link
>    <[7]http://ftp-master.metadata.debian.org/changelogs//main/l/linux/linux_4.14.13-1~bpo9+1_changelog>
>    which tells us that this corresponds to upstream release 4.14.13.
>    The upstream release was made on 10 January and this backports
>    package came on 14 January, so that's pretty swift.
> 
>    Newer kernels should be there now and there may well be one that deals
>    with both the meltdown and spectre vaulbnerabilities jointly.
> 
No!!!!!!!!!!

That is not at all how the backports repository is intended to be used.
I have been maintaining Debian packages for many years and I have on
occasion uploaded backports of my packages.

The packages in backports are not specifically supported by the security
team. They are supported only by the maintainer of the package (or the
uploader of the backport, as any Debain Developer can technically upload
backports of any package).

Security updates are nearly always handled by the security team,
somtimes with the support of the package maintainer (the kernel is a
good example where the maintainers do much of the heavy lifting). That
said, packages in the backports repository can easily be outdated (both
with respect the to the latest version in testing/unstable and with
respect to security fixes in stable).

Don't get me wrong, backports are immensely useful in some cases. In
particular, for the kernel, backports are quite handy when you need
support for newer hardware than what is available in stable. That said,
users of backports must understand that part of the cost of using
backports is that security fixes may be delayed, or may never arrive in
backports.

I understand what you are trying to advise the OP, but your reasoning is
all wrong. For someone running stable, the most secure configuration is
stable-only. In this particular instance it happens that there is a new
upstream release available in backports that addresses the specific
security vulnerability which concerns the OP. However, this is by far
the case for security vulnerabilities in general.

I would stronly recommend against your approach as a means to obtain
proper security fixes. It will inevitably lead to the mistaken
impression that a system is properly secured when it in fact may have
outstanding security vulnerabilities.

Regards,

-Roberto

-- 
Roberto C. Sánchez

[toc] | [prev] | [next] | [standalone]


#192742 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromAndy Smith <andy@strugglers.net>
Date2018-02-20 06:00 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vl8c1-4ll-5@gated-at.bofh.it>
In reply to#192663
Hello,

> On 19 February 2018 at 13:13, Turritopsis Dohrnii Teo En Ming <
> tdteoenming@gmail.com> wrote:
> 
> > What are the patches that I can download and install to be protected
> > against the Meltdown and Spectre security vulnerabilities?

The linux-kernel-* packages in Debian stable already have the KPTI
feature which protects you against Meltdown.

For variant 2 of Spectre you need a kernel with the so-called
retpoline feature that was also compiled with a compiler that
supports that feature. At the moment I think that the only packaged
kernel which has this (has feature and is compiled with new enough
gcc) is the one in unstable:

    <https://packages.debian.org/sid/linux-image-4.14.0-3-amd64>

Versions of gcc that have the retpoline feature backported into them
have already hit stable and oldstable (and maybe others; haven't
checked), so another alternative would be to compile your own
upstream kernel package using that gcc. Since Debian stable uses the
4.9.x long term stable kernel releases, you could use the latest
upstream of those. Anything past 4.9.77 has the retpoline feature.

Or just wait a bit longer for a kernel package that is compiled with
a newer gcc to arrive as a stable security update. This is probably
the most reasonable approach for the average user of Debian.

Patches for variant 1 of Spectre are still in development in the
upstream kernel, and in other software. You will also need updated
CPU microcode and possibly a new BIOS.

It is likely that there will be further exploit techniques
discovered in this general area, that will require different fixes.

There are some other considerations if your machine is not running
on bare metal. In that case you should check with your
virtualisation provider about that.

On Mon, Feb 19, 2018 at 01:23:25PM +0000, Michael Fothergill wrote:
> ​Checkout the debian backports suite (kindly resourcefully suggested by
> Andy Smith)

Please note that I provided these details to Michael Fothergill as
part of Michael's general query about how a user could obtain a
newer kernel package, not as an answer to how to obtain a kernel
that was secured against any particular thing.

Backports is not the correct answer for security purposes. Security
support in the backports suite is done by the package uploaders and
not the security team. Although, updates for the kernel packages do
tend to arrive pretty quickly so I personally would not feel too bad
about short term use of a backports kernel.

Cheers,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#192767 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-02-20 14:50 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vlgsV-1eA-1@gated-at.bofh.it>
In reply to#192742
On Tue, Feb 20, 2018 at 04:52:45AM +0000, Andy Smith wrote:
> Versions of gcc that have the retpoline feature backported into them
> have already hit stable and oldstable (and maybe others; haven't
> checked),

Just oldstable, actually.  Not stable yet.

<https://www.debian.org/security/2018/dsa-4117> is for oldstable only.

[toc] | [prev] | [next] | [standalone]


#192668 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2018-02-19 15:20 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkUsq-433-7@gated-at.bofh.it>
In reply to#192657
On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En Ming wrote:
> What are the patches that I can download and install to be protected
> against the Meltdown and Spectre security vulnerabilities?

Meltdown patch went out a month ago.

Spectre, see here:
https://security-tracker.debian.org/tracker/CVE-2017-5753

[toc] | [prev] | [next] | [standalone]


#192690 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-02-19 18:00 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkWXg-5wG-7@gated-at.bofh.it>
In reply to#192668

[Multipart message — attachments visible in raw view] — view raw

On 19 February 2018 at 14:10, Greg Wooledge <wooledg@eeg.ccf.org> wrote:

> On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En Ming
> wrote:
> > What are the patches that I can download and install to be protected
> > against the Meltdown and Spectre security vulnerabilities?
>
> Meltdown patch went out a month ago.
>
> Spectre, see here:
> https://security-tracker.debian.org/tracker/CVE-2017-5753


​Please excuse my extreme ignorance here, but there is something puzzling
me a bit in the spectre web page......

For the sid entry, the table says the following:

Source PackageReleaseVersionStatus
sid                                             4.15.4-1    vulnerable

I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if
you compiled it with gcc 7.3 then the spectre fix would then work.

Does the status indicator here refer to the spectre problem?

If it does why does it say vulnerable?

Is there something else causing a problem or barrier here that means you
can't use gcc 7.3 with what seems to be source code for this kernel
(maybe it's not the kernel source, please correct me here) or some other
confounding factor here?

Regards

MF









​

[toc] | [prev] | [next] | [standalone]


#192693 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromReco <recoverym4n@gmail.com>
Date2018-02-19 18:10 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkX6W-5Pi-35@gated-at.bofh.it>
In reply to#192690
	Hi.

On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote:
> I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if
> you compiled it with gcc 7.3 then the spectre fix would then work.

Not unless you apply the retpoline patch to the gcc.

For instance, just today said patch was applied to the Debian stable
version of gcc, gcc-4.9:

https://www.debian.org/security/2018/dsa-4117

Reco

[toc] | [prev] | [next] | [standalone]


#192699 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-02-19 18:50 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkXJD-621-7@gated-at.bofh.it>
In reply to#192693

[Multipart message — attachments visible in raw view] — view raw

On 19 February 2018 at 17:03, Reco <recoverym4n@gmail.com> wrote:

>         Hi.
>
> On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote:
> > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if
> > you compiled it with gcc 7.3 then the spectre fix would then work.
>
> Not unless you apply the retpoline patch to the gcc.
>
> For instance, just today said patch was applied to the Debian stable
> version of gcc, gcc-4.9:
>
> https://www.debian.org/security/2018/dsa-4117
>
> Reco
>
> ​Doesn't that mean that if you installed this version of gcc 4.9 and one
of the most recent kernels debian has e.g. 4.15.4-1 above
then it will be able to correct install the microcode or whatever it is
called and you don't need a compiler as new as gcc 7.3?

If so that is excellent news indeed.

No chrooting needed there......

Not a sausage of it.

You would have to run the compiler but the kernel source for 4.15.4-1 would
already be in the debian format.

So it should not be that difficult.

Regards

MF











​

[toc] | [prev] | [next] | [standalone]


#192702 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromReco <recoverym4n@gmail.com>
Date2018-02-19 19:10 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkY2Z-6qi-19@gated-at.bofh.it>
In reply to#192699
On Mon, Feb 19, 2018 at 05:24:18PM +0000, Michael Fothergill wrote:
> On 19 February 2018 at 17:03, Reco <recoverym4n@gmail.com> wrote:
> 
> >         Hi.
> >
> > On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote:
> > > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if
> > > you compiled it with gcc 7.3 then the spectre fix would then work.
> >
> > Not unless you apply the retpoline patch to the gcc.
> >
> > For instance, just today said patch was applied to the Debian stable
> > version of gcc, gcc-4.9:
> >
> > https://www.debian.org/security/2018/dsa-4117
> >
> > Reco
> >
> > Doesn't that mean that if you installed this version of gcc 4.9 and one
> of the most recent kernels debian has e.g. 4.15.4-1 above
> then it will be able to correct install the microcode or whatever it is
> called and you don't need a compiler as new as gcc 7.3?
> 
> If so that is excellent news indeed.

I'm unsure of linux-4.15, but it should be possible to use patched
gcc-4.9 to build backported linux-4.14+89. Whenever they applied the
second part of retpoline patch to this kernel remains to seen.

Being lazy I'll just wait while Debian Kernel Team builds a patched
kernel for all of us.

Reco

[toc] | [prev] | [next] | [standalone]


#192705 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Lange <klappnase@freenet.de>
Date2018-02-19 19:40 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkYw1-6Dg-17@gated-at.bofh.it>
In reply to#192702
On Mon, 19 Feb 2018 21:00:08 +0300
Reco <recoverym4n@gmail.com> wrote:

> On Mon, Feb 19, 2018 at 05:24:18PM +0000, Michael Fothergill wrote:
> > On 19 February 2018 at 17:03, Reco <recoverym4n@gmail.com> wrote:
> > 
> > >         Hi.
> > >
> > > On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote:
> > > > I had thought up to now that e.g. kernel 4.15.4-1 was new enough
> > > > that if you compiled it with gcc 7.3 then the spectre fix would
> > > > then work.
> > >
> > > Not unless you apply the retpoline patch to the gcc.
> > >
> > > For instance, just today said patch was applied to the Debian stable
> > > version of gcc, gcc-4.9:
> > >
> > > https://www.debian.org/security/2018/dsa-4117

I believe gcc-4.9 is "oldstable" (Jessie). 

Regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Totally illogical, there was no chance.
		-- Spock, "The Galileo Seven", stardate 2822.3

[toc] | [prev] | [next] | [standalone]


#192704 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Lange <klappnase@freenet.de>
Date2018-02-19 19:30 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkYmm-6zz-5@gated-at.bofh.it>
In reply to#192690
Hi,

On Mon, 19 Feb 2018 16:40:19 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:

> On 19 February 2018 at 14:10, Greg Wooledge <wooledg@eeg.ccf.org> wrote:
> 
> > On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En
> > Ming wrote:
> > > What are the patches that I can download and install to be protected
> > > against the Meltdown and Spectre security vulnerabilities?
> >
> > Meltdown patch went out a month ago.
> >
> > Spectre, see here:
> > https://security-tracker.debian.org/tracker/CVE-2017-5753
> 
> 
> ​Please excuse my extreme ignorance here, but there is something
> puzzling me a bit in the spectre web page......
> 
> For the sid entry, the table says the following:
> 
> Source PackageReleaseVersionStatus
> sid                                             4.15.4-1    vulnerable
> 
> I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if
> you compiled it with gcc 7.3 then the spectre fix would then work.
> 
> Does the status indicator here refer to the spectre problem?
> 
> If it does why does it say vulnerable?

There seems to be some confusion in this thread.
The page linked above refers to CVE-2017-5753 a.k.a. "Spectre-1".
You mean CVE-2017-5715 a.k.a. "Spectre-2".

Regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

It would be illogical to assume that all conditions remain stable.
		-- Spock, "The Enterprise Incident", stardate 5027.3

[toc] | [prev] | [next] | [standalone]


#192710 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-02-19 20:10 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkYZ4-72v-11@gated-at.bofh.it>
In reply to#192704

[Multipart message — attachments visible in raw view] — view raw

On 19 February 2018 at 18:24, Michael Lange <klappnase@freenet.de> wrote:

> Hi,
>
> On Mon, 19 Feb 2018 16:40:19 +0000
> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>
> > On 19 February 2018 at 14:10, Greg Wooledge <wooledg@eeg.ccf.org> wrote:
> >
> > > On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En
> > > Ming wrote:
> > > > What are the patches that I can download and install to be protected
> > > > against the Meltdown and Spectre security vulnerabilities?
> > >
> > > Meltdown patch went out a month ago.
> > >
> > > Spectre, see here:
> > > https://security-tracker.debian.org/tracker/CVE-2017-5753
> >
> >
> > ​Please excuse my extreme ignorance here, but there is something
> > puzzling me a bit in the spectre web page......
> >
> > For the sid entry, the table says the following:
> >
> > Source PackageReleaseVersionStatus
> > sid                                             4.15.4-1    vulnerable
> >
> > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if
> > you compiled it with gcc 7.3 then the spectre fix would then work.
> >
> > Does the status indicator here refer to the spectre problem?
> >
> > If it does why does it say vulnerable?
>
> There seems to be some confusion in this thread.
> The page linked above refers to CVE-2017-5753 a.k.a. "Spectre-1".
>

Are you saying that this link:
​
https://security-tracker.debian.org/tracker/CVE-2017-5753

​which looks like it should be going to a spectre 1 fix is actually a
discussion and tables etc
of the spectre 2 fixes that are in the pipeline ie it is incorrectly
labelled?

Cheers

MF​



> You mean CVE-2017-5715 a.k.a. "Spectre-2".
>
> Regards
>
> Michael
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> It would be illogical to assume that all conditions remain stable.
>                 -- Spock, "The Enterprise Incident", stardate 5027.3
>
>

[toc] | [prev] | [next] | [standalone]


#192714 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Lange <klappnase@freenet.de>
Date2018-02-19 20:20 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vkZ8K-75Q-15@gated-at.bofh.it>
In reply to#192710
Hi,

On Mon, 19 Feb 2018 18:46:15 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:

> Are you saying that this link:
> ​
> https://security-tracker.debian.org/tracker/CVE-2017-5753
> 
> ​which looks like it should be going to a spectre 1 fix is actually a
> discussion and tables etc
> of the spectre 2 fixes that are in the pipeline ie it is incorrectly
> labelled?

no, I meant to say that you were looking at the wrong place if you wanted
to see if the "spectre-2" fix has arrived in debian, for this one you
will have to look here:

https://security-tracker.debian.org/tracker/CVE-2017-5715

Regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

We'll pivot at warp 2 and bring all tubes to bear, Mr. Sulu!

[toc] | [prev] | [next] | [standalone]


#192730 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-02-19 22:30 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vl1ay-8oh-15@gated-at.bofh.it>
In reply to#192714

[Multipart message — attachments visible in raw view] — view raw

On 19 February 2018 at 19:10, Michael Lange <klappnase@freenet.de> wrote:

> Hi,
>
> On Mon, 19 Feb 2018 18:46:15 +0000
> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>
> > Are you saying that this link:
> > ​
> > https://security-tracker.debian.org/tracker/CVE-2017-5753
> >
> > ​which looks like it should be going to a spectre 1 fix is actually a
> > discussion and tables etc
> > of the spectre 2 fixes that are in the pipeline ie it is incorrectly
> > labelled?
>
> no, I meant to say that you were looking at the wrong place if you wanted
> to see if the "spectre-2" fix has arrived in debian, for this one you
> will have to look here:
>
> https://security-tracker.debian.org/tracker/CVE-2017-5715


​No, we were not looking for it.  I think a joint fix for meltdown and
spectre 1 would fit the bill at present .

I think this gcc 4.9 thing is an excellent development for this objective
and I salute it enthusiastically.

Regards

Michael​


>
>
> Regards
>
> Michael
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> We'll pivot at warp 2 and bring all tubes to bear, Mr. Sulu!
>
>

[toc] | [prev] | [next] | [standalone]


#192743 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromAndy Smith <andy@strugglers.net>
Date2018-02-20 06:10 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vl8lI-4DR-5@gated-at.bofh.it>
In reply to#192730
Hello,

On Mon, Feb 19, 2018 at 09:03:20PM +0000, Michael Fothergill wrote:
> On 19 February 2018 at 19:10, Michael Lange <klappnase@freenet.de> wrote:
> > no, I meant to say that you were looking at the wrong place if you wanted
> > to see if the "spectre-2" fix has arrived in debian, for this one you
> > will have to look here:
> >
> > https://security-tracker.debian.org/tracker/CVE-2017-5715
> 
> ​No, we were not looking for it.  I think a joint fix for meltdown and
> spectre 1 would fit the bill at present .

They are different bugs with different fixes. No one is even certain
HOW to fix Spectre variant 1 yet, or if it can be without entirely
new CPUs. Things have only got as far as kicking around ideas on how
to make exploiting it harder.

Your suggestion makes about as much sense as lumping every single
buffer overflow bug into one CVE and then saying almost all software
ever made is vulnerable, until there is one patch that fixes
everything at once.

Your comments along the lines of "I thought it was fixed…", as
Michael Lange pointed out, were about Spectre variant 2 but you are
looking at the security tracker page for Spectre variant 1.
CVE-2017-5753 is Spectre v1. There is no fix for Spectre v1 anywhere
yet, not even in Linux upstream.

Spectre v2, which you are talking about, is CVE-2017-5715, again as
Michael Lange just pointed out to you. As you can see from the link
that Michael gave you, Spectre v2 is fixed in the kernel package in
sid. Read it again:

    <https://security-tracker.debian.org/tracker/CVE-2017-5715>

That's the retpoline stuff you're talking about.

Cheers,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#192752 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-02-20 09:30 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vlbtg-6yV-5@gated-at.bofh.it>
In reply to#192743

[Multipart message — attachments visible in raw view] — view raw

On 20 February 2018 at 05:09, Andy Smith <andy@strugglers.net> wrote:

> Hello,
>
> On Mon, Feb 19, 2018 at 09:03:20PM +0000, Michael Fothergill wrote:
> > On 19 February 2018 at 19:10, Michael Lange <klappnase@freenet.de>
> wrote:
> > > no, I meant to say that you were looking at the wrong place if you
> wanted
> > > to see if the "spectre-2" fix has arrived in debian, for this one you
> > > will have to look here:
> > >
> > > https://security-tracker.debian.org/tracker/CVE-2017-5715
> >
> > ​No, we were not looking for it.  I think a joint fix for meltdown and
> > spectre 1 would fit the bill at present .
>
> They are different bugs with different fixes. No one is even certain
> HOW to fix Spectre variant 1 yet, or if it can be without entirely
> new CPUs. Things have only got as far as kicking around ideas on how
> to make exploiting it harder.
>
> Your suggestion makes about as much sense as lumping every single
> buffer overflow bug into one CVE and then saying almost all software
> ever made is vulnerable, until there is one patch that fixes
> everything at once.
>

​I think I just got Spectre 1 and 2 mixed up in the discussion.  I did not
think
the Spectre fix worked for the entirety of the the Spectre vulnerability.
​
​I also read in quite a few places that fixing all of it was an open ended
problem.​


>
> Your comments along the lines of "I thought it was fixed…", as
> Michael Lange pointed out, were about Spectre variant 2 but you are
> looking at the security tracker page for Spectre variant 1.
> CVE-2017-5753 is Spectre v1. There is no fix for Spectre v1 anywhere
> yet, not even in Linux upstream.
>
> Spectre v2, which you are talking about, is CVE-2017-5715, again as
> Michael Lange just pointed out to you. As you can see from the link
> that Michael gave you, Spectre v2 is fixed in the kernel package in
> sid. Read it again:
>
>     <https://security-tracker.debian.org/tracker/CVE-2017-5715>
>
> That's the retpoline stuff you're talking about.
>

​For me at any rate if the new version of gcc 4.9 makes it easier for a
new user to get access to that portion of Spectre vulnerability jointly
with the the availability of Meltdown as is, then as I said I would be
very pleased.  and if a third person comes on the site asking about
this problem then we could encourage them to try it.

Cheers

MF​




> Cheers,
> Andy
>
> --
> https://bitfolk.com/ -- No-nonsense VPS hosting
>
>

[toc] | [prev] | [next] | [standalone]


#192760 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Lange <klappnase@freenet.de>
Date2018-02-20 11:10 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vld21-7GJ-1@gated-at.bofh.it>
In reply to#192752
Hi,

On Tue, 20 Feb 2018 08:05:19 +0000
Michael Fothergill <michael.fothergill@gmail.com> wrote:

> ​For me at any rate if the new version of gcc 4.9 makes it easier for a
> new user to get access to that portion of Spectre vulnerability jointly
> with the the availability of Meltdown as is, then as I said I would be
> very pleased.  and if a third person comes on the site asking about
> this problem then we could encourage them to try it.

As I understood from what you wrote earlier you are using Buster, so why
not just stick with its default gcc-7 which from what
https://packages.debian.org/search?keywords=gcc-7&searchon=names&suite=testing&section=all
says has been updated to 7.3.0 which was iirc what you were waiting for.

Regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Deflector shields just came on, Captain.

[toc] | [prev] | [next] | [standalone]


#192773 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromMichael Fothergill <michael.fothergill@gmail.com>
Date2018-02-20 16:00 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vlhyG-1RP-15@gated-at.bofh.it>
In reply to#192760

[Multipart message — attachments visible in raw view] — view raw

On 20 February 2018 at 10:01, Michael Lange <klappnase@freenet.de> wrote:

> Hi,
>
> On Tue, 20 Feb 2018 08:05:19 +0000
> Michael Fothergill <michael.fothergill@gmail.com> wrote:
>
> > ​For me at any rate if the new version of gcc 4.9 makes it easier for a
> > new user to get access to that portion of Spectre vulnerability jointly
> > with the the availability of Meltdown as is, then as I said I would be
> > very pleased.  and if a third person comes on the site asking about
> > this problem then we could encourage them to try it.
>
> As I understood from what you wrote earlier you are using Buster, so why
> not just stick with its default gcc-7 which from what
> https://packages.debian.org/search?keywords=gcc-7&
> searchon=names&suite=testing&section=all
> says has been updated to 7.3.0 which was iirc what you were waiting for.
>

​I am not worried about what I would need personally to compile a kernel to
use in Debian.
I am currently using sid so there is no problem for me using e.g. gcc 7.3
etc.....

And installing new kernels in gentoo that I run is easy.

What interests me more here are the options for a new user.

Greg's latest post suggests the new gcc 4.9 only works in oldstable ie
jessie not stretch.

So perhaps I have to revise my thinking on this once again.....

Cheers

MF​


>
> Regards
>
> Michael
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> Deflector shields just came on, Captain.
>
>

[toc] | [prev] | [next] | [standalone]


#192753 — Re: Is Debian Linux protected against the Meltdown and Spectre security flaws?

FromStephan Seitz <stse+debian@fsing.rootsland.net>
Date2018-02-20 10:20 +0100
SubjectRe: Is Debian Linux protected against the Meltdown and Spectre security flaws?
Message-ID<vlcfD-764-11@gated-at.bofh.it>
In reply to#192743

[Multipart message — attachments visible in raw view] — view raw

On Di, Feb 20, 2018 at 05:09:12 +0000, Andy Smith wrote:
>CVE-2017-5753 is Spectre v1. There is no fix for Spectre v1 anywhere
>yet, not even in Linux upstream.

Are you sure?

CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1'
* Mitigated according to the /sys interface:  YES  (kernel confirms that the mitigation is active)
* Kernel has array_index_mask_nospec:  YES  (1 occurence(s) found of 64 bits array_index_mask_nospec())
* Checking count of LFENCE instructions following a jump in kernel:  NO  (only 3 jump-then-lfence instructions found, should be >= 30 (heuristic))
> STATUS:  NOT VULNERABLE  (Mitigation: __user pointer sanitization)

Kernel is Linux 4.15.4 #1 SMP Sat Feb 17 23:19:56 CET 2018 x86_64, 
compiled myself with gcc 7.3 from testing.

According to spectre-meltdown-checker all three vulnerabilities are 
mitigated.

Shade and sweet water!

	Stephan

-- 
| Public Keys: http://fsing.rootsland.net/~stse/keys.html |

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web