KernelCare did a fix for yesterday patches.
ubuntu-xenial-aws
ubuntu-trusty-lts-xenial
ubuntu-xenial
We have released patches for Meltdown vulnerability for above-mentioned distributions to the TEST feed. Our internal tests didn't reveal any crashes.
To deploy them:
edit /etc/sysconfig/kcare/kcare.conf
Add:
PREFIX=test
Run:
kcarectl --update
CHANGELOG:
ubuntu-trusty-lts-xenial:
CVE-2017-5754: Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Meltdown. A local attacker could use this to expose
sensitive information, including kernel memory.
cvelist: [CVE-2017-5754]
latest-version: 4.4.0-128.154~14.04.1
ubuntu-xenial:
CVE-2017-5754: Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Meltdown. A local attacker could use this to expose
sensitive information, including kernel memory.
cvelist: [CVE-2017-5754]
latest-version: 4.4.0-128.154
ubuntu-xenial-aws:
CVE-2017-5754: Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Meltdown. A local attacker could use this to expose
sensitive information, including kernel memory.
cvelist: [CVE-2017-5754]
latest-version: 4.4.0-1060.69
--
-- Regards,
Irina Semenova | Project Coordinator of KernelCare
Skype: iras535