cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
820
Views
0
Helpful
4
Replies

CPU Side-Channel Information Disclosure Vulnerabilities

Dragomir
Level 1
Level 1

How do I patch the intel cpu security vulnerability? Is this going to be a cisco firmware update or is it via vmware?

4 Replies 4

Dragomir
Level 1
Level 1

any idea?

Dragomir,

 

Jacob has a fairly good post about this. (see below)

 

https://communities.cisco.com/community/technology/datacenter/compute-and-storage/ucs_management/blog/2018/01/11/ucs-servers-and-the-impact-of-spectre-and-meltdown-vulnerabilities

 

"Finally, from a Cisco UCS perspective, we are planning to patch several versions of software which will be detailed in the Cisco Bug IDs referenced in the Cisco PSIRT advisory as release updated firmware."

 

There appear to be a few tentative release dates for patches from the UCS perspective already listed.

 

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

 

From an OS level perspective, I believe a few vendors have released a patch already that loads a fix, however that may be something to investigate further.

 

Below is a VMware Security Advisory going over one of the vulnerabilities, and it appears to have patched versions available.

 

Hope this helps.

https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html

 

Leo Laohoo
Hall of Fame
Hall of Fame
The date of release of the vulnerabilities are on 18 February 2018.
Without any inside information, I believe the fix will be in form of a CIMC firmware/patch.

Is the patch going to significant slow down the cpu processing?

Review Cisco Networking products for a $25 gift card