bk99.de entertain the web since 1997

Linux: kernel and distributions protect against the Foreshadow/L1TF processor flaw

Summary

In August 2018 the processor flaw Foreshadow, also known as L1 Terminal Fault (L1TF), became known in many Intel CPUs; the Linux main branch and major distributions immediately provided protection. Anyone running third-party virtual machines also had to switch off hyper-threading, which could cost VMs up to 50 percent of their performance. The stable and longterm kernels appeared after less than 24 hours of review.

Ideas

  • Countermeasures had been prepared for months under confidentiality.
  • The fixes reached the main branch and all important stable branches on the same day.
  • For hypervisor operators an update was not enough; hyper-threading had to be switched off.
  • Systems without virtual machines hardly lost any performance.

Insights

  • Hardware flaws shift the cost of security into performance losses in software.
  • Shared processor cores are a trust boundary that has to be drawn deliberately.

Facts

  • The flaws are listed as CVE-2018-3615, CVE-2018-3620 and CVE-2018-3646.
  • Fixed versions included 4.18.1, 4.14.63, 4.9.120 and 4.4.148.
  • Processors from other manufacturers were not affected.
  • Full protection also required microcode updates for the processor.
  • New kernel parameters control L1TF protection; hyper-threading remains active by default.

References

Critique

  • The figure of up to 50 percent performance loss comes from “Linux circles” and is not substantiated.

Recommendations

  • Check the protection status of your systems under /sys/devices/system/cpu/vulnerabilities.
  • Disable SMT on hypervisors that run guests of different trust levels.

Read the original article

Search the Web Archive