Linux: kernel and distributions protect against the Foreshadow/L1TF processor flaw
Summary
In August 2018 the processor flaw Foreshadow, also known as L1 Terminal Fault (L1TF), became known in many Intel CPUs; the Linux main branch and major distributions immediately provided protection. Anyone running third-party virtual machines also had to switch off hyper-threading, which could cost VMs up to 50 percent of their performance. The stable and longterm kernels appeared after less than 24 hours of review.
Ideas
- Countermeasures had been prepared for months under confidentiality.
- The fixes reached the main branch and all important stable branches on the same day.
- For hypervisor operators an update was not enough; hyper-threading had to be switched off.
- Systems without virtual machines hardly lost any performance.
Insights
- Hardware flaws shift the cost of security into performance losses in software.
- Shared processor cores are a trust boundary that has to be drawn deliberately.
Facts
- The flaws are listed as CVE-2018-3615, CVE-2018-3620 and CVE-2018-3646.
- Fixed versions included 4.18.1, 4.14.63, 4.9.120 and 4.4.148.
- Processors from other manufacturers were not affected.
- Full protection also required microcode updates for the processor.
- New kernel parameters control L1TF protection; hyper-threading remains active by default.
References
Critique
- The figure of up to 50 percent performance loss comes from “Linux circles” and is not substantiated.
Recommendations
- Check the protection status of your systems under /sys/devices/system/cpu/vulnerabilities.
- Disable SMT on hypervisors that run guests of different trust levels.
Links to the original source and the Web Archive open in a new tab.