[Bug 1891812] Re: Missing Linux Kernel Mitigations

2020-08-17 Thread Thadeu Lima de Souza Cascardo
https://aws.amazon.com/security/security-bulletins/AWS-2019-004/

According to Amazon advisory, fixes have been applied and "no customer
action is required at the Infrastructure level". Reading from other
sources [1], I can only conclude that Amazon has not provided the knobs
needed to do the mitigation. This explains the issue for MDS and TAA.
SSB is likely vulnerable for the same reasons, but I'll look for their
advisory and update it here. Same thing for ITLB multihit.

One possible avenue of investigation is verifying if VERW is being used
and providing the mitigation for the MDS case.

Regards.
Cascardo.

[1]
https://www.reddit.com/r/aws/comments/br38fl/sidechannel_md_clear_cpu_flags_not_being_passed/

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1891812

Title:
  Missing Linux Kernel Mitigations

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux-aws/+bug/1891812/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1891812] Re: Missing Linux Kernel Mitigations

2020-08-17 Thread Manfred Hampl
** Package changed: ubuntu => linux-aws (Ubuntu)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1891812

Title:
  Missing Linux Kernel Mitigations

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux-aws/+bug/1891812/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1891812] Re: Missing Linux Kernel Mitigations

2020-08-16 Thread Ubuntu Foundations Team Bug Bot
Thank you for taking the time to report this bug and helping to make
Ubuntu better.  It seems that your bug report is not filed about a
specific source package though, rather it is just filed against Ubuntu
in general.  It is important that bug reports be filed about source
packages so that people interested in the package can find the bugs
about it.  You can find some hints about determining what package your
bug might be about at https://wiki.ubuntu.com/Bugs/FindRightPackage.
You might also ask for help in the #ubuntu-bugs irc channel on Freenode.

To change the source package that this bug is filed about visit
https://bugs.launchpad.net/ubuntu/+bug/1891812/+editstatus and add the
package name in the text box next to the word Package.

[This is an automated message.  I apologize if it reached you
inappropriately; please just reply to this message indicating so.]

** Tags added: bot-comment

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1891812

Title:
  Missing Linux Kernel Mitigations

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+bug/1891812/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs