LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Virtualization and Cloud
User Name
Password
Linux - Virtualization and Cloud This forum is for the discussion of all topics relating to Linux Virtualization and Linux Cloud platforms. Xen, KVM, OpenVZ, VirtualBox, VMware, Linux-VServer and all other Linux Virtualization platforms are welcome. OpenStack, CloudStack, ownCloud, Cloud Foundry, Eucalyptus, Nimbus, OpenNebula and all other Linux Cloud platforms are welcome. Note that questions relating solely to non-Linux OS's should be asked in the General forum.

Notices


Reply
  Search this Thread
Old 01-10-2018, 12:38 PM   #1
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Rep: Reputation: 174Reputation: 174
Does the CPU in a virtual machine inherit the sins (vulnerabilities) of its father?


I am running VMWare Player 12.5.7 on a Dell Precision workstation with an Intel i7-6700 - CentOS 7 (as the host). This processor would appear to be in the population susceptible to Spectra & Meltdown.

If I fire up a CentOS 7 virtual machine on this host is the "virtual CPU" also susceptible?

How about if I run a 32 bit virtual machine such as a virtualized Windows 7 image made from a 32 bit physical machine? Or perhaps Ubuntu 32 bit built in VMWare player on the host?

By susceptible I am referring to an attack vector into the VM (from a web browser attach perhaps) getting to an encryption key in the memory of the VM. I am not considering an attack vector into the memory of the host and then into the memory of a VM which happens to be residing in the physical RAM of the host.

TIA,

Ken
 
Old 01-10-2018, 02:46 PM   #2
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,978

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
You will have to have all OS's updated usually. Not sure why you'd not update them all.


I don't know what would happen if you ran a qemu processor but I'd assume it is flawed too.
 
Old 01-10-2018, 03:31 PM   #3
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174
Thanks jefro, I DO update all of the systems. I was just wondering if visualization emulated vulnerabilities as well as other hardware features

I knew I should have bought a Dec Alpha based workstation some years ago. In only cost as much as a mid size car. As it is, the only machines which I have which are immune from the current vulnerabilities du jour are an ancient Pentium 4 desktop, an Intel Atom (under)powered netbook and a Raspberry Pi (which runs only 32 bit). I should never have gotten rid of my Osborne

Ken
 
Old 01-10-2018, 07:39 PM   #4
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,978

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
The threats continue everyday.

Not sure the DEC Alpha is immune now that you mention it. Wonder if it was tested? It does share a lot of design with newer intel processors I thought as DEC was parted out.

My neighbor was selling Alpha processors at one time for $5000 each in lots of 1000. Where I work at we still run them. A $25,000 system, seemingly well spent.
 
Old 01-11-2018, 08:03 AM   #5
Aeterna
Senior Member
 
Registered: Aug 2017
Location: Terra Mater
Distribution: VM Host: Slackware-current, VM Guests: Artix, Venom, antiX, Gentoo, FreeBSD, OpenBSD, OpenIndiana
Posts: 1,008

Rep: Reputation: Disabled
Quote:
Originally Posted by taylorkh View Post
I am running VMWare Player 12.5.7 on a Dell Precision workstation with an Intel i7-6700 - CentOS 7 (as the host). This processor would appear to be in the population susceptible to Spectra & Meltdown.

If I fire up a CentOS 7 virtual machine on this host is the "virtual CPU" also susceptible?

How about if I run a 32 bit virtual machine such as a virtualized Windows 7 image made from a 32 bit physical machine? Or perhaps Ubuntu 32 bit built in VMWare player on the host?

By susceptible I am referring to an attack vector into the VM (from a web browser attach perhaps) getting to an encryption key in the memory of the VM. I am not considering an attack vector into the memory of the host and then into the memory of a VM which happens to be residing in the physical RAM of the host.

TIA,

Ken
it looks like you are safe(r):
https://www.linuxglobal.com/meltdown...-technologies/
VMware and Virtualbox (in VT) are not vulnerable to Meltdown
Spectre allows to read guest memory

Don't use chrome (JIT) even with AMD CPU

hope this will help
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is base memory of virtual machine used when virtual machine is not running? ravisingh1 Linux - Virtualization and Cloud 3 04-09-2013 03:41 AM
Virtual Machine using 100% cpu jayadhanesh Linux - Software 2 06-06-2012 09:06 AM
CPU usage is high by KVM virtual machine leechaotang Linux - Kernel 1 11-30-2011 02:22 PM
[SOLVED] C++ classes - a matter of style? inherit or not inherit? worzel1968 Programming 25 03-21-2011 02:40 PM
LXer: Linux Vs. Unix: The Sins Of The Father? LXer Syndicated Linux News 0 10-02-2008 01:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Virtualization and Cloud

All times are GMT -5. The time now is 04:33 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration