[volunteers] Fwd: Update on meltdown for cnrychase.xen.prgmr.com - VPS reboot required

Sarah Newman newmans at sonic.net
Mon Jan 15 03:37:58 PST 2018


No action needed, just FYI.

Unless anyone objects I can do a poor mans HVM conversion for svlug when it's ready.

--Sarah

-------- Forwarded Message --------
Subject: Update on meltdown for cnrychase.xen.prgmr.com - VPS reboot required
Date: Mon, 15 Jan 2018 03:07:49 -0800
From: Prgmr.com Support <support at prgmr.com>
Reply-To: support at prgmr.com

Prgmr.com has been closely monitoring developments related to the information disclosure
vulnerabilities Meltdown/CVE-2017-5754 [1] and Spectre/CVE-5753 [2]. A mitigation for Meltdown and
Paravirtualized (PV) Xen virtual machines was formally released on January 11th. There is currently
no public proof of concept for exploiting Xen using Meltdown, but once this mitigation has been
available for some period of time we expect a proof of concept will be released publicly. Therefore
we would like to have this mitigation running for all PV VPSs as soon as possible.

We have already deployed the mitigation to the host server for cnrychase.xen.prgmr.com, but to take
effect it requires a full shutdown and restart of your VPS from the management console. Rebooting
inside the VPS will not work.

Log in to the management console and select option #3 (shutdown) followed by option #2 (start).  It
will take longer for your VPS to boot than previously.

If you do not complete this by Jan 17 05:00:00 UTC 2018 we will perform this for you in between Jan
17 05:00:00 UTC 2018 and Jan 17 11:00:00 UTC 2018.

The latest CentOS 6 kernel (2.6.32-696.18.7.el6.x86_64) as well as the CentOS 7 kernel
(3.10.0-693.11.6.el7.centos.plus.x86_64) do not boot under PV mode so you will need to select an
older kernel if you have updated your software recently and are running one of these distributions.

We started deploying the mitigation at around Jan 13 20:00 UTC 2018, and if you have performed a
shutdown/start operation since then, it is possible the mitigation has already been applied to your
VPS. If you need confirmation of whether this is true, please respond to this email.

While this mitigation protects each VPS from the others, it does not protect against the kernel
memory inside a given VPS from being read by user mode within the same VPS. To protect against this,
a VPS must both run natively in HVM mode and have patches similar to the KPTI patches for Linux
applied [3]. There is already discussion of KPTI-style patches for Xen which would prevent user
processes from reading kernel memory, however it is unlikely that they will be ready for several
months. [4]

If several months is too long to wait for those patches, or you are experiencing a prohibitive
performance impact after restarting your VPS, we can help you convert your VPS to run in HVM mode.
If you want to convert your VPS to run in HVM mode please write back with what distribution and
release you are running, the output of 'uname -a', the output of 'find /lib/modules/$(uname -r)',
and your kernel configuration if it is not a binary one distributed from an upstream. We are not
able to perform conversions for NetBSD at this time.

The mitigation, called Vixen, works by running your VPS inside of an HVM (hardware virtualization)
shim. The shim uses some memory inside of your VPS, so we added 80 MiB of RAM to your VPS to account
for the additional overhead of the shim.

We will be applying this same mitigation to our own systems starting at Jan 16 04:00:00 UTC 2018 and
ending at Jan 16 08:00:00 UTC 2018. Various services may be unavailable for a few minutes during
this time period, but your VPS will stay running.

We don't have a timeline yet for patching Spectre. The Xen project is still working on patches and
Intel is still working on the microcode updates required to support those patches. We hope something
will be available within the next couple of weeks. It is almost certain a host server reboot will be
required to apply patches for Spectre.

Updates and news that don't immediately have a service impact will be posted to our blog,
https://prgmr.com/blog, and a link to those will be posted on our twitter feed at
https://twitter.com/prgmrcom .

Regards,
Prgmr.com support
-----
You're receiving this email because this address is a primary or technical contact for an active
service at prgmr.com.  If you need this corrected please contact us at support at prgmr.com.
P.O. Box 61688, Sunnyvale, CA 94088-1681 | https://prgmr.com/

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754
[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5753
[3] https://en.wikipedia.org/wiki/Kernel_page-table_isolation#Meltdown_vulnerability_and_KPTI
[4] https://lists.xenproject.org/archives/html/xen-devel/2018-01/msg00274.html



More information about the volunteers mailing list