Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:111 - Updated 2.4 kernel packages fix multiple vulnerabilities

Simon Oosthoek <[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Fri, Jul 01, 2005 at 12:39:41AM -0400, Bob Puff wrote:
> Wouldn't this slow the box down, disabling HT?

Yes, I think this one has been exagerated by the media anyway, so I can
understand Mandriva is trying to err on the safe side, but it will slow down
machines that have HT capable CPUs for interactive use (as far as I
understand the workings of HT). 

I think it would be appropriate to offer an alternative kernel with the
other security fixes, but with HT enabled.
 
> >  Multiple vulnerabilities in the Linux kernel have been discovered 
> > and fixed in this update.  The following have been fixed in the 2.4 kernels:
> > 
> >  Colin Percival discovered a vulnerability in Intel's Hyper-Threading
> >  technology could allow a local user to use a malicious thread to create
> >  covert channels, monitor the execution of other threads, and obtain
> >  sensitive information such as cryptographic keys via a timing 
> > attack on memory cache misses.  This has been corrected by disabling 
> > HT support in all kernels (CAN-2005-0109).

I think the problem is only serious on a lightly loaded machine with very
sensitive data (private keys for encryption) in the level 1 cache.
This situation is so rare and hard to exploit that it is more a theoretical
problem than a serious threat to anyone's privacy or data-integrity.

Cheers

Simon
message.footer (text/plain, 232 B)
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.