LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-12-2018, 02:09 PM   #1
donald3.heckel
Member
 
Registered: Aug 2014
Posts: 60

Rep: Reputation: Disabled
Spectre and Meltdown Mitigation with Ubuntu 16.04


Greetings!

Recently, I ran a spectre and meltdown vulnerability checker to see if my Ubuntu system was vulnerable to these vulnerabilities. With my previous 4.15 kernel, the script showed it was not vulnerable until I upgraded to 4.16. I am currently compiling the latest kernels myself. Here is the output: https://pastebin.com/P6W9VVXG

The script I used is found here: https://github.com/speed47/spectre-meltdown-checker

It said that IBPB and retpoline were disabled and that they needed to be enabled. I currently upgraded gcc to 7.3.0 by building and compiling it manually to see if that would help. I am not sure if it did. :/

I would be curious if there is a good way to mitigate these vulnerabilities completely with my current setup.

Thank you in advance!


Sincerely,

donald3.heckel

Last edited by donald3.heckel; 04-12-2018 at 02:11 PM.
 
Old 04-14-2018, 09:10 PM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
I'd look here since I have no idea either...?

Good Luck!
 
Old 04-16-2018, 11:32 PM   #3
donald3.heckel
Member
 
Registered: Aug 2014
Posts: 60

Original Poster
Rep: Reputation: Disabled
Speculation of situations and alternatives

Hello Habitual!

Sorry for the delay in getting back to you as I have been very busy. I guess this can be a learning experience for the both of us. XD For the most part, I even tried hacking around with the Makefile to see if I could manually insert the flags -IBPB and/or -IBRS. I gave that a try and recompiled. Retpoline was already enabled, but it seemed like that did not work either. One other last ditch effort that I tried was installing stock versions from the Ubuntu repos. Unfortunately, that only made the status show my system vulnerable to all three CVEs and slowed my system down dramatically. I switched back to the kernels that I compiled myself and my system went back to being speedy without a hitch or those two vulnerabilities. It seemed that I was much better off configuring and compiling those kernels myself in Ubuntu to begin with. I just downloaded the latest 4.16.2 sources from kernel.org so that I can compile them myself and see what happens. I will let you all know!

I guess it seems what one guy in a different community I was in said cannot be more true: "Compiling so much stuff yourself in Ubuntu that you might as well use Arch".

Speaking of the whole 18.04 shakeup with the removal of unity and data collection compounded with Ubuntu's/Canonical's whole set of blunders in not really maintaining their stuff properly and getting cozy with Micro$oft, I guess the time is coming soon for me to switch to Fedora or CentOS. Out of curiosity, I ran the script on my i5 laptop running Fedora just to see the results. It wasn't vulnerable to any of the three CVEs! It seems that CentOS/Fedora/Red Hat seem to fix a great many things and holes ahead of others by patching the crap out of their kernels just when they come out. At least they are modern and not ancient! On my honorable relic (the great Core 2 Quad Q6600), I still haven't figured it out yet, but I guess I will keep looking to consider my options. Red Hat/Fedora/CentOS do a far superior job in taking security seriously as well as maintaining their repos properly. Let me know if you come up with anything else that might also be worth a look.


Sincerely,


donald3.heckel

Last edited by donald3.heckel; 04-17-2018 at 11:31 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Canonical Releases Spectre/Meltdown Patches for Ubuntu 17.10 for Raspberry Pi 2 LXer Syndicated Linux News 0 03-16-2018 05:14 PM
LXer: Purism Progress Report, Spectre Mitigation for Ubuntu, Malicious Chrome Extensions and More LXer Syndicated Linux News 0 01-19-2018 12:43 AM
Meltdown and Spectre ots3go Solaris / OpenSolaris 1 01-10-2018 04:15 AM
LXer: Canonical Will Soon Patch all Supported Ubuntu Releases Against Meltdown/Spectre LXer Syndicated Linux News 0 01-04-2018 03:10 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration