rssLink RSS for all categories
 
icon_orange
icon_blue
icon_orange
icon_orange
icon_red
icon_green
icon_green
icon_red
icon_red
icon_orange
icon_red
icon_green
icon_green
icon_orange
icon_orange
icon_red
icon_blue
icon_green
icon_red
icon_red
icon_green
icon_green
icon_red
icon_blue
icon_orange
icon_green
icon_green
icon_green
icon_green
icon_green
icon_red
 

FS#29259 — Meltdown / Spectre - VPS 2014

Attached to Project— VPS
Maintenance
Infrastructure
CLOSED
100%
Following the different CVE publicized :
- CVE-2017-5715 (branch target injection – Spectre)
- CVE-2017-5753 (bounds check bypass – Spectre)
- CVE-2017-5754 (rogue data cache load – Meltdown)

Variant 1: bounds check bypass (CVE-2017-5753) - spectre
Vulnerable : YES
Fixed by patch : YES

Variant 2: branch target injection (CVE-2017-5715) - spectre
Vulnerable : NO

Variant 3: rogue data cache load (CVE-2017-5754) - meltdown
Vulnerable : NO

======================================================================================================================================
VPS 2014 Cloud

Patches are dependent on OS environment : OVH is maintaining a list of vendors patches => http://travaux.ovh.net/?do=details&id=29257

======================================================================================================================================
VPS 2014 Classic

A new kernel is being prepared for vhost to fix Variant 1 based on: https://openvz.org/Download/kernel/rhel6/042stab127.2
Date:  Thursday, 11 January 2018, 00:05AM
Reason for closing:  Done
Comment by OVH - Monday, 08 January 2018, 11:49AM

07/01/2018 14:00:00
The kernel is out and is being tested at the moment.


Comment by OVH - Monday, 08 January 2018, 11:50AM

07/01/2018 21:00:00
The tests are conclusive, so we will proceed to an update of the kernel on the whole VPS Classic 2014 infrastructure.


Comment by OVH - Monday, 08 January 2018, 11:53AM

We will proceed to an update of the kernel on these first vhosts
- vhost25580
- vhost32109
- vhost25207
- vhost31951
- vhost22121

These vhosts will be rebooted at 08/01/2018 22:00:00.


Comment by OVH - Monday, 08 January 2018, 11:55AM

We will proceed to an update of the kernel on all CA vhosts.

These vhosts will be rebooted at 10/01/2018 10:00:00.


Comment by OVH - Monday, 08 January 2018, 11:56AM

We will proceed to an update of the kernel on all FR vhosts.

These vhosts will be rebooted at 10/01/2018 22:00:00.


Comment by OVH - Monday, 08 January 2018, 23:48PM

The update of these vhost is delayed to 10PM the 09/01/2018 :
- vhost25580
- vhost32109
- vhost25207
- vhost31951
- vhost22121


Comment by OVH - Tuesday, 09 January 2018, 23:24PM

The update of these vhost is now done :
- vhost25580
- vhost32109
- vhost25207
- vhost31951
- vhost22121


Comment by OVH - Wednesday, 10 January 2018, 10:34AM

The kernel upgrade on all CA vhosts is ongoing.

A service interruption of less than 15min is to be expected.


Comment by OVH - Wednesday, 10 January 2018, 11:49AM

The intervention on CA vhosts is now done.


Comment by OVH - Wednesday, 10 January 2018, 22:04PM

The kernel upgrade on all FR and FR-CA vhosts is ongoing.

A service interruption of less than 15min is to be expected.


Comment by OVH - Thursday, 11 January 2018, 00:04AM

The intervention on FR and FR-CA vhosts is now done.

All done