Bug 46188 - linux: Multiple security issues (4.1)
linux: Multiple security issues (4.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.1
Other Linux
: P2 normal (vote)
: UCS 4.1-5-errata
Assigned To: Arvid Requate
Felix Botner
https://security.googleblog.com/2018/...
:
Depends on: 45243 46029
Blocks:
  Show dependency treegraph
 
Reported: 2018-01-30 10:27 CET by Arvid Requate
Modified: 2018-01-31 14:34 CET (History)
8 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?: Yes
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2018010521000309
Bug group (optional): Security
Max CVSS v3 score: 8.2 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2018-01-30 10:27:26 CET
We should backport Kernel 4.9.78 to UCS 4.1-5

+++ This bug was initially created as a clone of Bug #46029 +++

* cpu: speculative execution bounds-check bypass (CVE-2017-5753)
* cpu: speculative execution branch target injection (CVE-2017-5715)CVE-2017-5715

Will probably require this:
- linux kernel update
- µcode update for Intel and AMD
- gcc update
- qemu update
- libvirtupdate

After that backport for UCS-4.1

+++ This bug was initially created as a clone of Bug #45981 +++
Comment 1 Arvid Requate univentionstaff 2018-01-30 10:59:37 CET
8e7c4cb: Advisories, copied from branch 4.2-3 and adjusted:

* linux.yaml
* univention-kernel-image-signed.yaml
* univention-kernel-image.yaml

Manual package update and reboot looked good:
* UCS 4.1-5 VM amd64
  > Spectre V2 mitigation: Mitigation: Full generic retpoline
* UCS 4.1-5 VM i386
  > Spectre V2 mitigation: Filling RSB on context switch
  > Spectre V2 mitigation: Mitigation: Full generic retpoline

Updated via univention-install univention-kernel-image
Comment 2 Felix Botner univentionstaff 2018-01-30 12:02:32 CET
OK - amd64/i386 (4.1-5 with ext updates)
OK - univention-install univention-kernel-image with 4.2-3 repo updates linux,
     univention-kernel-image and univention-kernel-image-signed
OK - reboot
OK - YAML files