Dear Customers,
We have released patches for Meltdown vulnerability for above-mentioned distributions. Our internal tests, as well as tests with live customers over the past two days, didn't reveal any crashes.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:
# /usr/bin/kcarectl --update
Chngelog:
cl7:
CVE-2017-5754: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to
an attacker with local user access via a side-channel analysis of the data cache.
cvelist: [CVE-2017-5754]
latest-version: 3.10.0-714.10.2.lve1.4.77.el7