Alert.png The wiki is deprecated and due to be decommissioned by the end of September 2022.
The content is being migrated to other supports, new updates will be ignored and lost.
If needed you can get in touch with EGI SDIS team using operations @ egi.eu.

Difference between revisions of "SVG:Meltdown and Spectre Vulnerabilities"

From EGIWiki
Jump to navigation Jump to search
Line 24: Line 24:


[https://security.web.cern.ch/security/advisories/spectre-meltdown/spectre-meltdown.shtml  https://security.web.cern.ch/security/advisories/spectre-meltdown/spectre-meltdown.shtml]
[https://security.web.cern.ch/security/advisories/spectre-meltdown/spectre-meltdown.shtml  https://security.web.cern.ch/security/advisories/spectre-meltdown/spectre-meltdown.shtml]
== Intel information ==
Product patches
[https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File
https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File]

Revision as of 10:59, 11 January 2018

Main page Software Security Checklist Issue Handling Advisories Notes On Risk Advisory Template More

Meltdown and Spectre Vulnerabilities


Baustelle.png This page is under construction.


Purpose of this page

To provide useful links and other information concerning the Meltdown and Spectre vulnerabilities.

What are they?

These are vulnerabilities in the design of the chip hardware, and cannot be fully resolved by patching operating systems. However patches are available which mitigate these problems.

Meltdown affects most Intel chips, and has CVE-2017-5754

Spectre affects a wide range of chips, CVE-2017-5753 and CVE-2017-5715.

These are described in the register at http://www.theregister.co.uk/2018/01/04/intel_amd_arm_cpu_vulnerability/

https://meltdownattack.com/ and https://spectreattack.com/

CERN information

CERN has compiled information which is useful for may EGI sites

https://security.web.cern.ch/security/advisories/spectre-meltdown/spectre-meltdown.shtml


Intel information

Product patches


[https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File https://downloadcenter.intel.com/download/27431/Linux-Processor-Microcode-Data-File]