spec_store_bypass and other vulnerabilities

Forum Forums New users New Users and General Questions spec_store_bypass and other vulnerabilities

  • This topic has 4 replies, 3 voices, and was last updated Sep 19-12:01 pm by anticapitalista.
Viewing 5 posts - 1 through 5 (of 5 total)
  • Author
    Posts
  • #41898
    Member
    anti-ewaste

      Hi guys, I got curious seeing the output of inxi -Fxxxrza on MX Linux so I looked at my other systems. On an AMD E-350 Bobcat with MX 19.2 there was just this one, but on my netbook with an old Celeron M processor running AntiX 17.2 there were several vulnerabilities.

      My question is does this mostly depend on the kernel version, BIOS updates, or both? Or is it a matter of how popular the CPU is, or what era it’s from and thus current support? I didn’t have any that weren’t mitigated with my i5 Ivy Bridge Desktop or the A6 notebook.

      • This topic was modified 2 years, 7 months ago by anti-ewaste.
      #41907
      Member
      Xecure
        Helpful
        Up
        0
        ::

        My question is does this mostly depend on the kernel version, BIOS updates, or both?

        Kernel version. Almost 100% CPU related vulnerabilities are patched in the kernel.
        anticapitalista spends time building 4.9.xxx and 4.19.xxx kernels for antix that include security updates and patches, so try updating the 4.9.xxx (if that is the one you are using) to its lates xxx version and see if the vulnerabilities are gone.

        Though some vulnerabilities are simply not patched if the CPU model is very old, so maybe even a kernel update might not help.

        antiX Live system enthusiast.
        General Live Boot Parameters for antiX.

        #41922
        Member
        anti-ewaste
          Helpful
          Up
          0
          ::

          The E-350 machine is already on 4.19.0-10, which appears to be the latest when I search apt-cache search linux-image.

          I’d imagine the more mainstream/unit sold CPU gets first priority even though this one was supposed to be a big deal when it came out. Looks like it was release Jan 2011..
          .

          • This reply was modified 2 years, 7 months ago by anti-ewaste.
          #41924
          Member
          Xecure
            Helpful
            Up
            0
            ::

            The E-350 machine is already on 4.19.0-10

            That is not the newest 4.19 antiX kernel, but the 4.19 debian kernel. I believe anticapitalista’s one is better for antiX.
            You can find it in the package installer (antiX kernel Meltdown … 4.19.143)
            or in cli-aptiX under “Search for antiX kernel”, and select the 4.19.143 one.
            sudo cli-aptiX

            See if, after choosing it during boot, you still have the vulnerabilities.
            You can always return to your previous Debian kernel if you are not satisfied.

            antiX Live system enthusiast.
            General Live Boot Parameters for antiX.

            #41925
            Forum Admin
            anticapitalista
              Helpful
              Up
              0
              ::

              You might need an older one. There is a 4.4.235 version in the repos.

              Philosophers have interpreted the world in many ways; the point is to change it.

              antiX with runit - leaner and meaner.

            Viewing 5 posts - 1 through 5 (of 5 total)
            • You must be logged in to reply to this topic.