Spectre/Meltdown attacks & KernelCare - update

10 views
Skip to first unread message

Igor Seletskiy

unread,
Jan 5, 2018, 10:59:09 AM1/5/18
to
Dear Clients,

I have updated our blog on the current state of things in regards of KernelCare patches for Spectre/Meltdown attacks.

Here is the summary of what we know, what we expect, and suggestions:

1. Fixes available should prevent 2 out of 3 possible attack vectors. Intel promises microcode updates next week to close all known attack vectors. Applying microcode typically requires reboot (but we will try to allow doing it via KC)
2. Exploit for meltdown is very simple, as long as attacker can execute arbitrary code, they can read everything in RAM
3. The patchset is big & complex. We also need to augment it with a lot of our own code to make it patchable with KernelCare, as we need to change the way existing / running processes access kernel space.

Even though we didn't hit any roadblocks today, I think our initial projection of Saturday was very optimistic. We need to continue not hitting any roadblocks to make it.

More realistic projection is Monday, due to complexity & number of components we need to bring together & make sure they all working.

My recommendation as of now would be:
* If you are a service provider where it is easy for an attacker to run arbitrary code, don't wait
* If you are in full control of your servers / enterprise / corp customer with no immediate access for hackers to run any code on your servers, and your risk tolerance is high enough, you might be able to hold off until we have a patch.

Note: We are still going to continue working through weekend/full force to get this patch out. This is just my suggestions best of the information available to me at this moment

Regards,
Igor Seletskiy |  CEO
CloudLinux OS   |   KernelCare   |   Imunify360

Get 24/7 free, exceptionally good support at cloudlinux.zendesk.com
Follow us on twitter for technical updates: @CloudLinuxOS
Reply all
Reply to author
Forward
0 new messages