Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:111 - Updated 2.4 kernel packages fix multiple vulnerabilities

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 1-Jul-05, at 1:39 AM, Simon Oosthoek wrote:

>> Wouldn't this slow the box down, disabling HT?
>>
>
> Yes, I think this one has been exagerated by the media anyway, so I  
> can
> understand Mandriva is trying to err on the safe side, but it will  
> slow down
> machines that have HT capable CPUs for interactive use (as far as I
> understand the workings of HT).
>
> I think it would be appropriate to offer an alternative kernel with  
> the
> other security fixes, but with HT enabled.

I believe you can enable HT with a boot-time option (ie. in lilo.conf  
or grub); I think it's just disabled by default to, yes, err on the  
side of safety.

If you don't care, by all means re-enable it.

>>>  Multiple vulnerabilities in the Linux kernel have been discovered
>>> and fixed in this update.  The following have been fixed in the  
>>> 2.4 kernels:
>>>
>>>  Colin Percival discovered a vulnerability in Intel's Hyper- 
>>> Threading
>>>  technology could allow a local user to use a malicious thread to  
>>> create
>>>  covert channels, monitor the execution of other threads, and obtain
>>>  sensitive information such as cryptographic keys via a timing
>>> attack on memory cache misses.  This has been corrected by disabling
>>> HT support in all kernels (CAN-2005-0109).
>>>
>
> I think the problem is only serious on a lightly loaded machine  
> with very
> sensitive data (private keys for encryption) in the level 1 cache.
> This situation is so rare and hard to exploit that it is more a  
> theoretical
> problem than a serious threat to anyone's privacy or data-integrity.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.