Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade kernels to 4.4.142+ #3646

Closed
emkll opened this issue Jul 19, 2018 · 2 comments
Closed

Upgrade kernels to 4.4.142+ #3646

emkll opened this issue Jul 19, 2018 · 2 comments
Milestone

Comments

@emkll
Copy link
Contributor

emkll commented Jul 19, 2018

Description

Spectre v4 fixes have been backported to 4.4.142. We should upgrade SecureDrop kernels to 4.4.142 or above.

User Research Evidence

Users like up to date software.

User Stories

As a SecureDrop admin, I would like to run up-to-date kernels.

@emkll emkll added this to the 0.9 milestone Jul 19, 2018
@emkll
Copy link
Contributor Author

emkll commented Jul 25, 2018

Successfully built and did preliminary testing with 4.4.144 on hardware, and everything appears to be functioning correctly.

However, to obtain full mitigations against Spectre versions v3a and v4, CPU microcode updates [0] are also required, and are not yet available in Trusty [1].
Note that we currently do not have intel-microcode as a dependency on servers, as the January Spectre/Meltdown variants had kernel-level mitigations. The risk should be quite low, however, as these vulnerabilities require code execution on the hosts.

[0] : https://downloadcenter.intel.com/search?keyword=linux+microcode
[1] : https://launchpad.net/ubuntu/+source/intel-microcode

@emkll
Copy link
Contributor Author

emkll commented Jul 27, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant