HomeinetMeltdown and Spectre: When an entire Red Hat backs down...

Meltdown and Spectre: When an entire Red Hat backs down…

Red Hat has released updates that roll back previous patches fixing the Spectre vulnerability (Variant 2, also known as CVE-2017-5715) after the company's customers reported that some systems were failing to boot.

"Red Hat is no longer providing microcode to address Spectre, variant 2, due to the uncertainties that have arisen and are causing difficulties booting our customers' systems," the company said.

Instead of updates, Red Hat recommends that each of its customers contact their hardware OEM to patch the CVE-2017-5715 vulnerability on a per-system basis.Red Hat
In addition to the Red Hat Enterprise Linux distribution, other RHEL-based distributions, such as CentOS and Scientific Linux, will be affected by Red Hat's decision to roll back previous updates for Spectre Variant 2. So everyone using RHEL and forks of the distribution should also contact their CPU/OEM vendors.
Recall that CVE-2017-5715 is the identification number for one of the three bugs known as Meltdown (CVE-2017-5754) and Spectre (Variant 1 – CVE-2017-5753, but also Variant 2 – CVE-2017-5715).
Most experts have said that only Meltdown and Spectre Variant 1 could theoretically be addressed through an OS update, but Spectre Variant 2 requires parallel firmware/BIOS/microcode updates to be fully patched.
As we reported in a previous post, Werner Haas, a representative of Cyberus Technology and a member of one of the three independent teams that discovered and reported Meltdown, said that achieving comprehensive protection against Spectre is not simple and will likely involve an “ongoing process” of software fixes and hardware modifications.
“The [Spectre] attack scenario is not that simple, as it is very possible that there will be cross-application attacks without even the OS being involved,” Haas said.
“So a blanket solution like Meltdown seems unlikely. Therefore, I expect combined hardware/software fixes along with the caveat that combating Spectre will be an ongoing process.”
The Spectre patching process is complex and difficult for all hardware and software vendors. So Red Hat’s pull of the updates and the company’s suggestion for patching by CPU makers and OEMs is no surprise.
Microsoft had to stop rolling out Spectre updates to AMD computers after they encountered similar issues that prevented PCs from booting. The company released those updates much later after working with AMD to resolve the issues.
Intel is facing the same issues in older Broadwell and Haswell processors.
It is worth mentioning that immediately after the vulnerabilities were announced, CERT announced that the only way to fix Meltdown and Spectre was to replace the CPU.
“The underlying vulnerability is primarily caused by design choices in the CPU architecture,” CERT researchers wrote. “Full removal of the vulnerability requires replacing the vulnerable CPU.”
Shortly after, and without anyone knowing what was being played out under the table, CERT retracted the notice, and Intel spokesperson Agnes Kwan stated: “CERT has updated the vulnerability note to correct some inaccuracies.”
Of course, we wouldn’t expect Intel to say anything different, since admitting the CERT report would cause major upheaval for the company, with the corresponding financial cost.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS