Red Hat Says Security Updates for Meltdown
The Meltdown and Spectre vulnerabilities (CVE-2017-5753, CVE-2017-5715, and CVE-2017-5754) were publicly disclosed earlier today as critical hardware flaws affecting modern microprocessors made in the last two decades. These can be exploited by an unprivileged attacker to bypass hardware restrictions through three unique attack paths and gain read access to privileged memory.
Red Hat Product Security provided us with several resources to better understand the impact of these hardware bugs on any of their supported Linux-based operating systems from an open source technology perspective. They said that Intel, AMD, POWER 8, POWER 9, IBM System z, and ARM chips are affected by the newly discovered vulnerabilities.
"These vulnerabilities have a broad impact on the IT industry, affecting many modern microprocessors and enabling an attacker to bypass restrictions to gain read access to privileged memory which would otherwise be inaccessible through side-channels," said Denise Dumas, VP of Operating System Platform at Red Hat. "In short, these vulnerabilities could allow a malicious actor to steal sensitive information from almost any computer, mobile device, or cloud deployment."
According to Red Hat, the affected operating systems include Red Hat Enterprise Linux 7.x, 6.x, and 5.x series, Red Hat Enterprise Linux for Real Time, for SAP Applications, for SAP HANA, and for SAP Solutions, Red Hat Enterprise MRG 2, Red Hat OpenShift 3.x and 2.x series, Red Hat Virtualization (RHEV-H/RHV-H) 4.1 and 3.6, as well as Red Hat OpenStack Platform 12, 11, 10, 9, 8, 7, and 6.
"Red Hat rates the security impact of the vulnerabilities as important"
The company will soon release new versions of the kernel, kernel-rt, kernel-headers, dracut, libvirt, qemu-kvm-rhev, microcode_clt, and linux_firmware components for the supported operating systems mentioned above, and said that it also included the ability to enable them selectively to better understand the impact of each one of these security updates on sensitive workloads.
Red Hat has rated the security impact of these vulnerabilities as important, stating that "this flaw requires an attacker to have local access to the affected system." However, they urge users to update their systems immediately to the new kernel versions it will release shortly even if they don't think their current configuration poses a direct threat to attacks.
相关热词:
本站内容来源于网络,如有侵权请与我们联系,我们会及时删除,我们深感抱歉!
注:本站所有信息仅供用于网络技术学习参考,学习中请遵循相关法律法规!
本文地址: https://www.juheyunku.com/xt/linux/7603.shtml
相关文章
热门TAG
命令 权重 外链 企业网站 白帽 php 织梦教程 dedecms修改内容 javascript 织梦 功能 标签 调用 详解 服务器 网站流量 实例解析 Dedecms 织梦cms HTML tags标签 python jquery教程 jquery windows SEO优化 蜘蛛 搜索引擎 网站收录 JSP最新文章
-
Linux 运维需要掌握的 17 个
时间:2020-12-28
-
这里有好用又好看的Linu
时间:2020-12-28
-
使用Meld在Linux中以图形方
时间:2020-12-28
-
Linux kernel swear counts
时间:2020-12-25
-
linux 防御SYN攻击步骤详解
时间:2020-12-23
-
谈谈Linux运维人员是否需要
时间:2020-12-23
-
linux的mount(挂载)命令详
时间:2020-12-23
-
Zotero:一款帮助你收集和
时间:2020-12-23
热门文章
-
Anki:让记忆更轻松的开源神器
时间:2020-12-22
-
如何在Linux启动时自动启动LXD容器
时间:2020-12-22
-
使用Vi/Vim编辑器:基础篇
时间:2020-12-22
-
使用parallel利用起你的所有CPU资源
时间:2020-12-22
-
Zsync:一个仅下载文件新的部分的传输工
时间:2020-12-22
-
linux 防御SYN攻击步骤详解
时间:2020-12-23
-
Vim普通模式的一般性规律性总结
时间:2020-12-22
-
TLP帮助我们的Linux机器节能省电
时间:2020-12-22
-
用户操作系统Unix的前世今生
时间:2020-12-23
-
谈谈Linux里10个最危险的命令
时间:2020-12-23
