We have released patches for Meltdown vulnerability for above-mentioned distributions. Our internal tests didn't reveal any crashes.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:
# /usr/bin/kcarectl --update
If you see any issues with the server -- contact our support.
CHANGELOG:
ubuntu-trusty-lts-xenial:
CVE-2017-5754: Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Meltdown. A local attacker could use this to expose
sensitive information, including kernel memory.
cvelist: [CVE-2017-5754]
latest-version: 4.4.0-128.154~14.04.1
ubuntu-xenial:
CVE-2017-5754: Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Meltdown. A local attacker could use this to expose
sensitive information, including kernel memory.
cvelist: [CVE-2017-5754]
latest-version: 4.4.0-128.154
ubuntu-xenial-aws:
CVE-2017-5754: Jann Horn discovered that microprocessors utilizing speculative execution
and indirect branch prediction may allow unauthorized memory reads via sidechannel
attacks. This flaw is known as Meltdown. A local attacker could use this to expose
sensitive information, including kernel memory.
cvelist: [CVE-2017-5754]
latest-version: 4.4.0-1060.69