Forum › Forums › New users › New Users and General Questions › spec_store_bypass and other vulnerabilities
- This topic has 4 replies, 3 voices, and was last updated Sep 19-12:01 pm by anticapitalista.
-
AuthorPosts
-
September 18, 2020 at 8:07 pm #41898Member
anti-ewaste
Hi guys, I got curious seeing the output of inxi -Fxxxrza on MX Linux so I looked at my other systems. On an AMD E-350 Bobcat with MX 19.2 there was just this one, but on my netbook with an old Celeron M processor running AntiX 17.2 there were several vulnerabilities.
My question is does this mostly depend on the kernel version, BIOS updates, or both? Or is it a matter of how popular the CPU is, or what era it’s from and thus current support? I didn’t have any that weren’t mitigated with my i5 Ivy Bridge Desktop or the A6 notebook.
- This topic was modified 2 years, 7 months ago by anti-ewaste.
September 19, 2020 at 1:28 am #41907Member
Xecure
::My question is does this mostly depend on the kernel version, BIOS updates, or both?
Kernel version. Almost 100% CPU related vulnerabilities are patched in the kernel.
anticapitalista spends time building 4.9.xxx and 4.19.xxx kernels for antix that include security updates and patches, so try updating the 4.9.xxx (if that is the one you are using) to its lates xxx version and see if the vulnerabilities are gone.Though some vulnerabilities are simply not patched if the CPU model is very old, so maybe even a kernel update might not help.
antiX Live system enthusiast.
General Live Boot Parameters for antiX.September 19, 2020 at 11:21 am #41922Member
anti-ewaste
::The E-350 machine is already on 4.19.0-10, which appears to be the latest when I search apt-cache search linux-image.
I’d imagine the more mainstream/unit sold CPU gets first priority even though this one was supposed to be a big deal when it came out. Looks like it was release Jan 2011..
.- This reply was modified 2 years, 7 months ago by anti-ewaste.
September 19, 2020 at 11:48 am #41924Member
Xecure
::The E-350 machine is already on 4.19.0-10
That is not the newest 4.19 antiX kernel, but the 4.19 debian kernel. I believe anticapitalista’s one is better for antiX.
You can find it in the package installer (antiX kernel Meltdown … 4.19.143)
or in cli-aptiX under “Search for antiX kernel”, and select the 4.19.143 one.
sudo cli-aptiXSee if, after choosing it during boot, you still have the vulnerabilities.
You can always return to your previous Debian kernel if you are not satisfied.antiX Live system enthusiast.
General Live Boot Parameters for antiX.September 19, 2020 at 12:01 pm #41925Forum Admin
anticapitalista
::You might need an older one. There is a 4.4.235 version in the repos.
Philosophers have interpreted the world in many ways; the point is to change it.
antiX with runit - leaner and meaner.
-
AuthorPosts
- You must be logged in to reply to this topic.