Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:111 - Updated 2.4 kernel packages fix multiple vulnerabilities
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 1-Jul-05, at 1:39 AM, Simon Oosthoek wrote:
>> Wouldn't this slow the box down, disabling HT?
>>
>
> Yes, I think this one has been exagerated by the media anyway, so I
> can
> understand Mandriva is trying to err on the safe side, but it will
> slow down
> machines that have HT capable CPUs for interactive use (as far as I
> understand the workings of HT).
>
> I think it would be appropriate to offer an alternative kernel with
> the
> other security fixes, but with HT enabled.
I believe you can enable HT with a boot-time option (ie. in lilo.conf
or grub); I think it's just disabled by default to, yes, err on the
side of safety.
If you don't care, by all means re-enable it.
>>> Multiple vulnerabilities in the Linux kernel have been discovered
>>> and fixed in this update. The following have been fixed in the
>>> 2.4 kernels:
>>>
>>> Colin Percival discovered a vulnerability in Intel's Hyper-
>>> Threading
>>> technology could allow a local user to use a malicious thread to
>>> create
>>> covert channels, monitor the execution of other threads, and obtain
>>> sensitive information such as cryptographic keys via a timing
>>> attack on memory cache misses. This has been corrected by disabling
>>> HT support in all kernels (CAN-2005-0109).
>>>
>
> I think the problem is only serious on a lightly loaded machine
> with very
> sensitive data (private keys for encryption) in the level 1 cache.
> This situation is so rare and hard to exploit that it is more a
> theoretical
> problem than a serious threat to anyone's privacy or data-integrity.
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed