On 01/04/2018 12:01 PM, Matthew Miller wrote:
On Thu, Jan 04, 2018 at 05:49:15AM -0800, Jonathan Ryshpan wrote:
What do people know about Fedora vs. the Meltdown and Spectre bugs?

Mitigation for Meltdown is in place in the kernel updates we released
yesterday. (Thanks to kernel team, release engineering, infrastructure
/ security, and qa!) Updates for Spectre should be coming in soon.



Meltdown - CVE-2017-5754 - is not mentioned in the koji kernel builds.

But should we be worried about Meltdown even without kpti for:

An internet facing headless laptop acting as a router. No local users. No X. No browsers. The only private info on the machine is ssh keys, and the local root password. Any potential problem ?

This machine is _very_ remote, running FC 25. We haven't updated to 26 because dnf remote update fails 2-3 times each update, leaving dups and a mess. We only update when we have someone there, which won't be for another 2 months.

Can we sleep at night ?

sean

_______________________________________________
users mailing list -- users@lists.fedoraproject.org
To unsubscribe send an email to users-le...@lists.fedoraproject.org

Reply via email to