[volunteers] Update on meltdown for svlug.xen.prgmr.com - VPS reboot required

Sarah Newman newmans at sonic.net
Mon Jan 15 03:40:29 PST 2018


... and that was the wrong email to forward (it's not so late it's early or anything...)

Pretend it said svlug.xen.prgmr.com originally.

On 01/15/2018 03:37 AM, Sarah Newman wrote:
> No action needed, just FYI.
>
> Unless anyone objects I can do a poor mans HVM conversion for svlug when it's ready.
>
> --Sarah
>

On 01/15/2018 03:34 AM, Prgmr.com Support wrote:
> Hi Sarah,
> 
> Prgmr.com has been closely monitoring developments related to the information disclosure
> vulnerabilities Meltdown/CVE-2017-5754 [1] and Spectre/CVE-5753 [2]. A mitigation for Meltdown and
> Paravirtualized (PV) Xen virtual machines was formally released on January 11th. There is currently
> no public proof of concept for exploiting Xen using Meltdown, but once this mitigation has been
> available for some period of time we expect a proof of concept will be released publicly. Therefore
> we would like to have this mitigation running for all PV VPSs as soon as possible.
> 
> We have already deployed the mitigation to the host server for svlug.xen.prgmr.com, but to take
> effect it requires a full shutdown and restart of your VPS from the management console. Rebooting
> inside the VPS will not work.
> 
> Log in to the management console and select option #3 (shutdown) followed by option #2 (start).  It
> will take longer for your VPS to boot than previously.
> 
> If you do not complete this by Jan 17 05:00:00 UTC 2018 we will perform this for you in between Jan
> 17 05:00:00 UTC 2018 and Jan 17 11:00:00 UTC 2018.
> 
> The latest CentOS 6 kernel (2.6.32-696.18.7.el6.x86_64) as well as the CentOS 7 kernel
> (3.10.0-693.11.6.el7.centos.plus.x86_64) do not boot under PV mode so you will need to select an
> older kernel if you have updated your software recently and are running one of these distributions.
> 
> We started deploying the mitigation at around Jan 13 20:00 UTC 2018, and if you have performed a
> shutdown/start operation since then, it is possible the mitigation has already been applied to your
> VPS. If you need confirmation of whether this is true, please respond to this email.
> 
> While this mitigation protects each VPS from the others, it does not protect against the kernel
> memory inside a given VPS from being read by user mode within the same VPS. To protect against this,
> a VPS must both run natively in HVM mode and have patches similar to the KPTI patches for Linux
> applied [3]. There is already discussion of KPTI-style patches for Xen which would prevent user
> processes from reading kernel memory, however it is unlikely that they will be ready for several
> months. [4]
> 
> If several months is too long to wait for those patches, or you are experiencing a prohibitive
> performance impact after restarting your VPS, we can help you convert your VPS to run in HVM mode.
> If you want to convert your VPS to run in HVM mode please write back with what distribution and
> release you are running, the output of 'uname -a', the output of 'find /lib/modules/$(uname -r)',
> and your kernel configuration if it is not a binary one distributed from an upstream. We are not
> able to perform conversions for NetBSD at this time.
> 
> The mitigation, called Vixen, works by running your VPS inside of an HVM (hardware virtualization)
> shim. The shim uses some memory inside of your VPS, so we added 80 MiB of RAM to your VPS to account
> for the additional overhead of the shim.
> 
> We will be applying this same mitigation to our own systems starting at Jan 16 04:00:00 UTC 2018 and
> ending at Jan 16 08:00:00 UTC 2018. Various services may be unavailable for a few minutes during
> this time period, but your VPS will stay running.
> 
> We don't have a timeline yet for patching Spectre. The Xen project is still working on patches and
> Intel is still working on the microcode updates required to support those patches. We hope something
> will be available within the next couple of weeks. It is almost certain a host server reboot will be
> required to apply patches for Spectre.
> 
> Updates and news that don't immediately have a service impact will be posted to our blog,
> https://prgmr.com/blog, and a link to those will be posted on our twitter feed at
> https://twitter.com/prgmrcom .
> 
> Regards,
> Prgmr.com support
> -----
> You're receiving this email because this address is a primary or technical contact for an active
> service at prgmr.com.  If you need this corrected please contact us at support at prgmr.com.
> P.O. Box 61688, Sunnyvale, CA 94088-1681 | https://prgmr.com/
> 
> [1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754
> [2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5753
> [3] https://en.wikipedia.org/wiki/Kernel_page-table_isolation#Meltdown_vulnerability_and_KPTI
> [4] https://lists.xenproject.org/archives/html/xen-devel/2018-01/msg00274.html
> 




More information about the volunteers mailing list