Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #192657 > unrolled thread
| Started by | Turritopsis Dohrnii Teo En Ming <tdteoenming@gmail.com> |
|---|---|
| First post | 2018-02-19 14:20 +0100 |
| Last post | 2018-02-27 17:10 +0100 |
| Articles | 20 on this page of 29 — 11 participants |
Back to article view | Back to linux.debian.user
Is Debian Linux protected against the Meltdown and Spectre security flaws? Turritopsis Dohrnii Teo En Ming <tdteoenming@gmail.com> - 2018-02-19 14:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 14:40 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Roberto C. Sánchez <roberto@debian.org> - 2018-02-19 15:30 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 06:00 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-20 14:50 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-19 15:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 18:00 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Reco <recoverym4n@gmail.com> - 2018-02-19 18:10 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 18:50 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Reco <recoverym4n@gmail.com> - 2018-02-19 19:10 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:40 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:30 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 20:10 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 20:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-19 22:30 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 06:10 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-20 09:30 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-20 11:10 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Fothergill <michael.fothergill@gmail.com> - 2018-02-20 16:00 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Stephan Seitz <stse+debian@fsing.rootsland.net> - 2018-02-20 10:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Andy Smith <andy@strugglers.net> - 2018-02-20 16:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Brad Rogers <brad@fineby.me.uk> - 2018-02-19 15:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-19 19:40 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Brad Rogers <brad@fineby.me.uk> - 2018-02-19 20:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Gene Heskett <gheskett@shentel.net> - 2018-02-19 21:30 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Greg Wooledge <wooledg@eeg.ccf.org> - 2018-02-19 21:50 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Michael Lange <klappnase@freenet.de> - 2018-02-20 00:20 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Gene Heskett <gheskett@shentel.net> - 2018-02-20 00:30 +0100
Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? Vincent Lefevre <vincent@vinc17.net> - 2018-02-27 17:10 +0100
Page 1 of 2 [1] 2 Next page →
| From | Turritopsis Dohrnii Teo En Ming <tdteoenming@gmail.com> |
|---|---|
| Date | 2018-02-19 14:20 +0100 |
| Subject | Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkTwm-3uw-7@gated-at.bofh.it> |
What are the patches that I can download and install to be protected against the Meltdown and Spectre security vulnerabilities? ===BEGIN SIGNATURE=== Turritopsis Dohrnii Teo En Ming's Academic Qualifications as at 30 Oct 2017 [1] https://tdtemcerts.wordpress.com/ [2] http://tdtemcerts.blogspot.sg/ [3] https://www.scribd.com/user/270125049/Teo-En-Ming ===END SIGNATURE===
[toc] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-02-19 14:40 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkTPH-3AI-5@gated-at.bofh.it> |
| In reply to | #192657 |
[Multipart message — attachments visible in raw view] — view raw
On 19 February 2018 at 13:13, Turritopsis Dohrnii Teo En Ming <
tdteoenming@gmail.com> wrote:
> What are the patches that I can download and install to be protected
> against the Meltdown and Spectre security vulnerabilities?
>
> ===BEGIN SIGNATURE===
>
> Turritopsis Dohrnii Teo En Ming's Academic Qualifications as at 30 Oct 2017
>
> [1] https://tdtemcerts.wordpress.com/
>
> [2] http://tdtemcerts.blogspot.sg/
>
> [3] https://www.scribd.com/user/270125049/Teo-En-Ming
>
> ===END SIGNATURE===
>
Checkout the debian backports suite (kindly resourcefully suggested by
Andy Smith)
Easiest thing to do when requiring a newer kernel would be to check
the backports suite, so in this case in stretch-backports we find
linux-image-amd64:
<https://packages.debian.org/stretch-backports/linux-image-amd64>
That's a virtual package that gets you the latest real kernel
package available in that suite, which right now is
linux-image-4.14.0-0.bpo.3-amd64:
<https://packages.debian.org/stretch-backports/linux-image-amd64>
>From there, if you look on the right you will see the Debian
changelog link
<http://ftp-master.metadata.debian.org/changelogs//main/l/
linux/linux_4.14.13-1~bpo9+1_changelog>
which tells us that this corresponds to upstream release 4.14.13.
The upstream release was made on 10 January and this backports
package came on 14 January, so that's pretty swift.
Newer kernels should be there now and there may well be one that deals with
both the meltdown and spectre vaulbnerabilities jointly.
Regards
Michael Fothergill
[toc] | [prev] | [next] | [standalone]
| From | Roberto C. Sánchez <roberto@debian.org> |
|---|---|
| Date | 2018-02-19 15:30 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkUC5-46d-13@gated-at.bofh.it> |
| In reply to | #192663 |
On Mon, Feb 19, 2018 at 01:23:25PM +0000, Michael Fothergill wrote: > > Checkout the debian backports suite (kindly resourcefully suggested by > Andy Smith) > Easiest thing to do when requiring a newer kernel would be to check > the backports suite, so in this case in stretch-backports we find > linux-image-amd64: > > <[5]https://packages.debian.org/stretch-backports/linux-image-amd64> > > That's a virtual package that gets you the latest real kernel > package available in that suite, which right now is > linux-image-4.14.0-0.bpo.3-amd64: > > <[6]https://packages.debian.org/stretch-backports/linux-image-amd64> > > >From there, if you look on the right you will see the Debian > changelog link > <[7]http://ftp-master.metadata.debian.org/changelogs//main/l/linux/linux_4.14.13-1~bpo9+1_changelog> > which tells us that this corresponds to upstream release 4.14.13. > The upstream release was made on 10 January and this backports > package came on 14 January, so that's pretty swift. > > Newer kernels should be there now and there may well be one that deals > with both the meltdown and spectre vaulbnerabilities jointly. > No!!!!!!!!!! That is not at all how the backports repository is intended to be used. I have been maintaining Debian packages for many years and I have on occasion uploaded backports of my packages. The packages in backports are not specifically supported by the security team. They are supported only by the maintainer of the package (or the uploader of the backport, as any Debain Developer can technically upload backports of any package). Security updates are nearly always handled by the security team, somtimes with the support of the package maintainer (the kernel is a good example where the maintainers do much of the heavy lifting). That said, packages in the backports repository can easily be outdated (both with respect the to the latest version in testing/unstable and with respect to security fixes in stable). Don't get me wrong, backports are immensely useful in some cases. In particular, for the kernel, backports are quite handy when you need support for newer hardware than what is available in stable. That said, users of backports must understand that part of the cost of using backports is that security fixes may be delayed, or may never arrive in backports. I understand what you are trying to advise the OP, but your reasoning is all wrong. For someone running stable, the most secure configuration is stable-only. In this particular instance it happens that there is a new upstream release available in backports that addresses the specific security vulnerability which concerns the OP. However, this is by far the case for security vulnerabilities in general. I would stronly recommend against your approach as a means to obtain proper security fixes. It will inevitably lead to the mistaken impression that a system is properly secured when it in fact may have outstanding security vulnerabilities. Regards, -Roberto -- Roberto C. Sánchez
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2018-02-20 06:00 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vl8c1-4ll-5@gated-at.bofh.it> |
| In reply to | #192663 |
Hello,
> On 19 February 2018 at 13:13, Turritopsis Dohrnii Teo En Ming <
> tdteoenming@gmail.com> wrote:
>
> > What are the patches that I can download and install to be protected
> > against the Meltdown and Spectre security vulnerabilities?
The linux-kernel-* packages in Debian stable already have the KPTI
feature which protects you against Meltdown.
For variant 2 of Spectre you need a kernel with the so-called
retpoline feature that was also compiled with a compiler that
supports that feature. At the moment I think that the only packaged
kernel which has this (has feature and is compiled with new enough
gcc) is the one in unstable:
<https://packages.debian.org/sid/linux-image-4.14.0-3-amd64>
Versions of gcc that have the retpoline feature backported into them
have already hit stable and oldstable (and maybe others; haven't
checked), so another alternative would be to compile your own
upstream kernel package using that gcc. Since Debian stable uses the
4.9.x long term stable kernel releases, you could use the latest
upstream of those. Anything past 4.9.77 has the retpoline feature.
Or just wait a bit longer for a kernel package that is compiled with
a newer gcc to arrive as a stable security update. This is probably
the most reasonable approach for the average user of Debian.
Patches for variant 1 of Spectre are still in development in the
upstream kernel, and in other software. You will also need updated
CPU microcode and possibly a new BIOS.
It is likely that there will be further exploit techniques
discovered in this general area, that will require different fixes.
There are some other considerations if your machine is not running
on bare metal. In that case you should check with your
virtualisation provider about that.
On Mon, Feb 19, 2018 at 01:23:25PM +0000, Michael Fothergill wrote:
> Checkout the debian backports suite (kindly resourcefully suggested by
> Andy Smith)
Please note that I provided these details to Michael Fothergill as
part of Michael's general query about how a user could obtain a
newer kernel package, not as an answer to how to obtain a kernel
that was secured against any particular thing.
Backports is not the correct answer for security purposes. Security
support in the backports suite is done by the package uploaders and
not the security team. Although, updates for the kernel packages do
tend to arrive pretty quickly so I personally would not feel too bad
about short term use of a backports kernel.
Cheers,
Andy
--
https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2018-02-20 14:50 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vlgsV-1eA-1@gated-at.bofh.it> |
| In reply to | #192742 |
On Tue, Feb 20, 2018 at 04:52:45AM +0000, Andy Smith wrote: > Versions of gcc that have the retpoline feature backported into them > have already hit stable and oldstable (and maybe others; haven't > checked), Just oldstable, actually. Not stable yet. <https://www.debian.org/security/2018/dsa-4117> is for oldstable only.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2018-02-19 15:20 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkUsq-433-7@gated-at.bofh.it> |
| In reply to | #192657 |
On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En Ming wrote: > What are the patches that I can download and install to be protected > against the Meltdown and Spectre security vulnerabilities? Meltdown patch went out a month ago. Spectre, see here: https://security-tracker.debian.org/tracker/CVE-2017-5753
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-02-19 18:00 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkWXg-5wG-7@gated-at.bofh.it> |
| In reply to | #192668 |
[Multipart message — attachments visible in raw view] — view raw
On 19 February 2018 at 14:10, Greg Wooledge <wooledg@eeg.ccf.org> wrote: > On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En Ming > wrote: > > What are the patches that I can download and install to be protected > > against the Meltdown and Spectre security vulnerabilities? > > Meltdown patch went out a month ago. > > Spectre, see here: > https://security-tracker.debian.org/tracker/CVE-2017-5753 Please excuse my extreme ignorance here, but there is something puzzling me a bit in the spectre web page...... For the sid entry, the table says the following: Source PackageReleaseVersionStatus sid 4.15.4-1 vulnerable I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if you compiled it with gcc 7.3 then the spectre fix would then work. Does the status indicator here refer to the spectre problem? If it does why does it say vulnerable? Is there something else causing a problem or barrier here that means you can't use gcc 7.3 with what seems to be source code for this kernel (maybe it's not the kernel source, please correct me here) or some other confounding factor here? Regards MF
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-02-19 18:10 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkX6W-5Pi-35@gated-at.bofh.it> |
| In reply to | #192690 |
Hi. On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote: > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if > you compiled it with gcc 7.3 then the spectre fix would then work. Not unless you apply the retpoline patch to the gcc. For instance, just today said patch was applied to the Debian stable version of gcc, gcc-4.9: https://www.debian.org/security/2018/dsa-4117 Reco
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-02-19 18:50 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkXJD-621-7@gated-at.bofh.it> |
| In reply to | #192693 |
[Multipart message — attachments visible in raw view] — view raw
On 19 February 2018 at 17:03, Reco <recoverym4n@gmail.com> wrote: > Hi. > > On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote: > > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if > > you compiled it with gcc 7.3 then the spectre fix would then work. > > Not unless you apply the retpoline patch to the gcc. > > For instance, just today said patch was applied to the Debian stable > version of gcc, gcc-4.9: > > https://www.debian.org/security/2018/dsa-4117 > > Reco > > Doesn't that mean that if you installed this version of gcc 4.9 and one of the most recent kernels debian has e.g. 4.15.4-1 above then it will be able to correct install the microcode or whatever it is called and you don't need a compiler as new as gcc 7.3? If so that is excellent news indeed. No chrooting needed there...... Not a sausage of it. You would have to run the compiler but the kernel source for 4.15.4-1 would already be in the debian format. So it should not be that difficult. Regards MF
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-02-19 19:10 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkY2Z-6qi-19@gated-at.bofh.it> |
| In reply to | #192699 |
On Mon, Feb 19, 2018 at 05:24:18PM +0000, Michael Fothergill wrote: > On 19 February 2018 at 17:03, Reco <recoverym4n@gmail.com> wrote: > > > Hi. > > > > On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote: > > > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if > > > you compiled it with gcc 7.3 then the spectre fix would then work. > > > > Not unless you apply the retpoline patch to the gcc. > > > > For instance, just today said patch was applied to the Debian stable > > version of gcc, gcc-4.9: > > > > https://www.debian.org/security/2018/dsa-4117 > > > > Reco > > > > Doesn't that mean that if you installed this version of gcc 4.9 and one > of the most recent kernels debian has e.g. 4.15.4-1 above > then it will be able to correct install the microcode or whatever it is > called and you don't need a compiler as new as gcc 7.3? > > If so that is excellent news indeed. I'm unsure of linux-4.15, but it should be possible to use patched gcc-4.9 to build backported linux-4.14+89. Whenever they applied the second part of retpoline patch to this kernel remains to seen. Being lazy I'll just wait while Debian Kernel Team builds a patched kernel for all of us. Reco
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-02-19 19:40 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkYw1-6Dg-17@gated-at.bofh.it> |
| In reply to | #192702 |
On Mon, 19 Feb 2018 21:00:08 +0300 Reco <recoverym4n@gmail.com> wrote: > On Mon, Feb 19, 2018 at 05:24:18PM +0000, Michael Fothergill wrote: > > On 19 February 2018 at 17:03, Reco <recoverym4n@gmail.com> wrote: > > > > > Hi. > > > > > > On Mon, Feb 19, 2018 at 04:40:19PM +0000, Michael Fothergill wrote: > > > > I had thought up to now that e.g. kernel 4.15.4-1 was new enough > > > > that if you compiled it with gcc 7.3 then the spectre fix would > > > > then work. > > > > > > Not unless you apply the retpoline patch to the gcc. > > > > > > For instance, just today said patch was applied to the Debian stable > > > version of gcc, gcc-4.9: > > > > > > https://www.debian.org/security/2018/dsa-4117 I believe gcc-4.9 is "oldstable" (Jessie). Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. Totally illogical, there was no chance. -- Spock, "The Galileo Seven", stardate 2822.3
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-02-19 19:30 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkYmm-6zz-5@gated-at.bofh.it> |
| In reply to | #192690 |
Hi, On Mon, 19 Feb 2018 16:40:19 +0000 Michael Fothergill <michael.fothergill@gmail.com> wrote: > On 19 February 2018 at 14:10, Greg Wooledge <wooledg@eeg.ccf.org> wrote: > > > On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En > > Ming wrote: > > > What are the patches that I can download and install to be protected > > > against the Meltdown and Spectre security vulnerabilities? > > > > Meltdown patch went out a month ago. > > > > Spectre, see here: > > https://security-tracker.debian.org/tracker/CVE-2017-5753 > > > Please excuse my extreme ignorance here, but there is something > puzzling me a bit in the spectre web page...... > > For the sid entry, the table says the following: > > Source PackageReleaseVersionStatus > sid 4.15.4-1 vulnerable > > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if > you compiled it with gcc 7.3 then the spectre fix would then work. > > Does the status indicator here refer to the spectre problem? > > If it does why does it say vulnerable? There seems to be some confusion in this thread. The page linked above refers to CVE-2017-5753 a.k.a. "Spectre-1". You mean CVE-2017-5715 a.k.a. "Spectre-2". Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. It would be illogical to assume that all conditions remain stable. -- Spock, "The Enterprise Incident", stardate 5027.3
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-02-19 20:10 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkYZ4-72v-11@gated-at.bofh.it> |
| In reply to | #192704 |
[Multipart message — attachments visible in raw view] — view raw
On 19 February 2018 at 18:24, Michael Lange <klappnase@freenet.de> wrote: > Hi, > > On Mon, 19 Feb 2018 16:40:19 +0000 > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > > On 19 February 2018 at 14:10, Greg Wooledge <wooledg@eeg.ccf.org> wrote: > > > > > On Mon, Feb 19, 2018 at 09:13:42PM +0800, Turritopsis Dohrnii Teo En > > > Ming wrote: > > > > What are the patches that I can download and install to be protected > > > > against the Meltdown and Spectre security vulnerabilities? > > > > > > Meltdown patch went out a month ago. > > > > > > Spectre, see here: > > > https://security-tracker.debian.org/tracker/CVE-2017-5753 > > > > > > Please excuse my extreme ignorance here, but there is something > > puzzling me a bit in the spectre web page...... > > > > For the sid entry, the table says the following: > > > > Source PackageReleaseVersionStatus > > sid 4.15.4-1 vulnerable > > > > I had thought up to now that e.g. kernel 4.15.4-1 was new enough that if > > you compiled it with gcc 7.3 then the spectre fix would then work. > > > > Does the status indicator here refer to the spectre problem? > > > > If it does why does it say vulnerable? > > There seems to be some confusion in this thread. > The page linked above refers to CVE-2017-5753 a.k.a. "Spectre-1". > Are you saying that this link: https://security-tracker.debian.org/tracker/CVE-2017-5753 which looks like it should be going to a spectre 1 fix is actually a discussion and tables etc of the spectre 2 fixes that are in the pipeline ie it is incorrectly labelled? Cheers MF > You mean CVE-2017-5715 a.k.a. "Spectre-2". > > Regards > > Michael > > .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. > > It would be illogical to assume that all conditions remain stable. > -- Spock, "The Enterprise Incident", stardate 5027.3 > >
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-02-19 20:20 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vkZ8K-75Q-15@gated-at.bofh.it> |
| In reply to | #192710 |
Hi, On Mon, 19 Feb 2018 18:46:15 +0000 Michael Fothergill <michael.fothergill@gmail.com> wrote: > Are you saying that this link: > > https://security-tracker.debian.org/tracker/CVE-2017-5753 > > which looks like it should be going to a spectre 1 fix is actually a > discussion and tables etc > of the spectre 2 fixes that are in the pipeline ie it is incorrectly > labelled? no, I meant to say that you were looking at the wrong place if you wanted to see if the "spectre-2" fix has arrived in debian, for this one you will have to look here: https://security-tracker.debian.org/tracker/CVE-2017-5715 Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. We'll pivot at warp 2 and bring all tubes to bear, Mr. Sulu!
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-02-19 22:30 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vl1ay-8oh-15@gated-at.bofh.it> |
| In reply to | #192714 |
[Multipart message — attachments visible in raw view] — view raw
On 19 February 2018 at 19:10, Michael Lange <klappnase@freenet.de> wrote: > Hi, > > On Mon, 19 Feb 2018 18:46:15 +0000 > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > > Are you saying that this link: > > > > https://security-tracker.debian.org/tracker/CVE-2017-5753 > > > > which looks like it should be going to a spectre 1 fix is actually a > > discussion and tables etc > > of the spectre 2 fixes that are in the pipeline ie it is incorrectly > > labelled? > > no, I meant to say that you were looking at the wrong place if you wanted > to see if the "spectre-2" fix has arrived in debian, for this one you > will have to look here: > > https://security-tracker.debian.org/tracker/CVE-2017-5715 No, we were not looking for it. I think a joint fix for meltdown and spectre 1 would fit the bill at present . I think this gcc 4.9 thing is an excellent development for this objective and I salute it enthusiastically. Regards Michael > > > Regards > > Michael > > .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. > > We'll pivot at warp 2 and bring all tubes to bear, Mr. Sulu! > >
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2018-02-20 06:10 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vl8lI-4DR-5@gated-at.bofh.it> |
| In reply to | #192730 |
Hello,
On Mon, Feb 19, 2018 at 09:03:20PM +0000, Michael Fothergill wrote:
> On 19 February 2018 at 19:10, Michael Lange <klappnase@freenet.de> wrote:
> > no, I meant to say that you were looking at the wrong place if you wanted
> > to see if the "spectre-2" fix has arrived in debian, for this one you
> > will have to look here:
> >
> > https://security-tracker.debian.org/tracker/CVE-2017-5715
>
> No, we were not looking for it. I think a joint fix for meltdown and
> spectre 1 would fit the bill at present .
They are different bugs with different fixes. No one is even certain
HOW to fix Spectre variant 1 yet, or if it can be without entirely
new CPUs. Things have only got as far as kicking around ideas on how
to make exploiting it harder.
Your suggestion makes about as much sense as lumping every single
buffer overflow bug into one CVE and then saying almost all software
ever made is vulnerable, until there is one patch that fixes
everything at once.
Your comments along the lines of "I thought it was fixed…", as
Michael Lange pointed out, were about Spectre variant 2 but you are
looking at the security tracker page for Spectre variant 1.
CVE-2017-5753 is Spectre v1. There is no fix for Spectre v1 anywhere
yet, not even in Linux upstream.
Spectre v2, which you are talking about, is CVE-2017-5715, again as
Michael Lange just pointed out to you. As you can see from the link
that Michael gave you, Spectre v2 is fixed in the kernel package in
sid. Read it again:
<https://security-tracker.debian.org/tracker/CVE-2017-5715>
That's the retpoline stuff you're talking about.
Cheers,
Andy
--
https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-02-20 09:30 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vlbtg-6yV-5@gated-at.bofh.it> |
| In reply to | #192743 |
[Multipart message — attachments visible in raw view] — view raw
On 20 February 2018 at 05:09, Andy Smith <andy@strugglers.net> wrote: > Hello, > > On Mon, Feb 19, 2018 at 09:03:20PM +0000, Michael Fothergill wrote: > > On 19 February 2018 at 19:10, Michael Lange <klappnase@freenet.de> > wrote: > > > no, I meant to say that you were looking at the wrong place if you > wanted > > > to see if the "spectre-2" fix has arrived in debian, for this one you > > > will have to look here: > > > > > > https://security-tracker.debian.org/tracker/CVE-2017-5715 > > > > No, we were not looking for it. I think a joint fix for meltdown and > > spectre 1 would fit the bill at present . > > They are different bugs with different fixes. No one is even certain > HOW to fix Spectre variant 1 yet, or if it can be without entirely > new CPUs. Things have only got as far as kicking around ideas on how > to make exploiting it harder. > > Your suggestion makes about as much sense as lumping every single > buffer overflow bug into one CVE and then saying almost all software > ever made is vulnerable, until there is one patch that fixes > everything at once. > I think I just got Spectre 1 and 2 mixed up in the discussion. I did not think the Spectre fix worked for the entirety of the the Spectre vulnerability. I also read in quite a few places that fixing all of it was an open ended problem. > > Your comments along the lines of "I thought it was fixed…", as > Michael Lange pointed out, were about Spectre variant 2 but you are > looking at the security tracker page for Spectre variant 1. > CVE-2017-5753 is Spectre v1. There is no fix for Spectre v1 anywhere > yet, not even in Linux upstream. > > Spectre v2, which you are talking about, is CVE-2017-5715, again as > Michael Lange just pointed out to you. As you can see from the link > that Michael gave you, Spectre v2 is fixed in the kernel package in > sid. Read it again: > > <https://security-tracker.debian.org/tracker/CVE-2017-5715> > > That's the retpoline stuff you're talking about. > For me at any rate if the new version of gcc 4.9 makes it easier for a new user to get access to that portion of Spectre vulnerability jointly with the the availability of Meltdown as is, then as I said I would be very pleased. and if a third person comes on the site asking about this problem then we could encourage them to try it. Cheers MF > Cheers, > Andy > > -- > https://bitfolk.com/ -- No-nonsense VPS hosting > >
[toc] | [prev] | [next] | [standalone]
| From | Michael Lange <klappnase@freenet.de> |
|---|---|
| Date | 2018-02-20 11:10 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vld21-7GJ-1@gated-at.bofh.it> |
| In reply to | #192752 |
Hi, On Tue, 20 Feb 2018 08:05:19 +0000 Michael Fothergill <michael.fothergill@gmail.com> wrote: > For me at any rate if the new version of gcc 4.9 makes it easier for a > new user to get access to that portion of Spectre vulnerability jointly > with the the availability of Meltdown as is, then as I said I would be > very pleased. and if a third person comes on the site asking about > this problem then we could encourage them to try it. As I understood from what you wrote earlier you are using Buster, so why not just stick with its default gcc-7 which from what https://packages.debian.org/search?keywords=gcc-7&searchon=names&suite=testing§ion=all says has been updated to 7.3.0 which was iirc what you were waiting for. Regards Michael .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. Deflector shields just came on, Captain.
[toc] | [prev] | [next] | [standalone]
| From | Michael Fothergill <michael.fothergill@gmail.com> |
|---|---|
| Date | 2018-02-20 16:00 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vlhyG-1RP-15@gated-at.bofh.it> |
| In reply to | #192760 |
[Multipart message — attachments visible in raw view] — view raw
On 20 February 2018 at 10:01, Michael Lange <klappnase@freenet.de> wrote: > Hi, > > On Tue, 20 Feb 2018 08:05:19 +0000 > Michael Fothergill <michael.fothergill@gmail.com> wrote: > > > For me at any rate if the new version of gcc 4.9 makes it easier for a > > new user to get access to that portion of Spectre vulnerability jointly > > with the the availability of Meltdown as is, then as I said I would be > > very pleased. and if a third person comes on the site asking about > > this problem then we could encourage them to try it. > > As I understood from what you wrote earlier you are using Buster, so why > not just stick with its default gcc-7 which from what > https://packages.debian.org/search?keywords=gcc-7& > searchon=names&suite=testing§ion=all > says has been updated to 7.3.0 which was iirc what you were waiting for. > I am not worried about what I would need personally to compile a kernel to use in Debian. I am currently using sid so there is no problem for me using e.g. gcc 7.3 etc..... And installing new kernels in gentoo that I run is easy. What interests me more here are the options for a new user. Greg's latest post suggests the new gcc 4.9 only works in oldstable ie jessie not stretch. So perhaps I have to revise my thinking on this once again..... Cheers MF > > Regards > > Michael > > .-.. .. ...- . .-.. --- -. --. .- -. -.. .--. .-. --- ... .--. . .-. > > Deflector shields just came on, Captain. > >
[toc] | [prev] | [next] | [standalone]
| From | Stephan Seitz <stse+debian@fsing.rootsland.net> |
|---|---|
| Date | 2018-02-20 10:20 +0100 |
| Subject | Re: Is Debian Linux protected against the Meltdown and Spectre security flaws? |
| Message-ID | <vlcfD-764-11@gated-at.bofh.it> |
| In reply to | #192743 |
[Multipart message — attachments visible in raw view] — view raw
On Di, Feb 20, 2018 at 05:09:12 +0000, Andy Smith wrote: >CVE-2017-5753 is Spectre v1. There is no fix for Spectre v1 anywhere >yet, not even in Linux upstream. Are you sure? CVE-2017-5753 [bounds check bypass] aka 'Spectre Variant 1' * Mitigated according to the /sys interface: YES (kernel confirms that the mitigation is active) * Kernel has array_index_mask_nospec: YES (1 occurence(s) found of 64 bits array_index_mask_nospec()) * Checking count of LFENCE instructions following a jump in kernel: NO (only 3 jump-then-lfence instructions found, should be >= 30 (heuristic)) > STATUS: NOT VULNERABLE (Mitigation: __user pointer sanitization) Kernel is Linux 4.15.4 #1 SMP Sat Feb 17 23:19:56 CET 2018 x86_64, compiled myself with gcc 7.3 from testing. According to spectre-meltdown-checker all three vulnerabilities are mitigated. Shade and sweet water! Stephan -- | Public Keys: http://fsing.rootsland.net/~stse/keys.html |
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web