[SOLVED]January 9, 2018: Has anyone received the promised security updates for Meltdown?

Chat about just about anything else
Post Reply
Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

[SOLVED]January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Tue Jan 09, 2018 12:08 pm

I just wondered if anybody has received the kernel security patches which were due to roll out today?
Last edited by Marziano on Wed Jan 10, 2018 7:37 am, edited 1 time in total.
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

User avatar
xenopeek
Level 24
Level 24
Posts: 22176
Joined: Wed Jul 06, 2011 3:58 am
Location: The Netherlands

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by xenopeek » Tue Jan 09, 2018 12:33 pm

No, as they are not released yet. You can follow progress here: https://wiki.ubuntu.com/SecurityTeam/Kn ... ndMeltdown

Firefox has already been updated on all Linux Mint editions and that has mitigation built in so that JavaScript can't exploit these bugs. What other untrusted code do you run on your system, aside from JavaScript from websites? For most home users upgrading their web browser effectively removes the theoretical threat that these bugs pose.
Image

Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Tue Jan 09, 2018 12:36 pm

Alright, thank you for your reply!
The only applications whose PPA I have added to my sources are Grub Customizer, Ukuu and Firefox Nightly.
I have installed Chrome dev edition as well by downloading the .deb-file from the official site. The PPA was added automatically to the Software Sources.
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

User avatar
xenopeek
Level 24
Level 24
Posts: 22176
Joined: Wed Jul 06, 2011 3:58 am
Location: The Netherlands

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by xenopeek » Tue Jan 09, 2018 1:06 pm

You should check yourself if those web browsers from those repositories already include the mitigation. I can only speak for Firefox from Linux Mint's repositories.
Image

Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Tue Jan 09, 2018 1:34 pm

I know that Firefox Nightly does include the patches. I suppose that Chrome Dev also has them implemented since the feature were going to be included in version 54 and above but I have to check that out. BTW, do you think installing JavaScript blocker extension is good as a second line of defence?
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

User avatar
xenopeek
Level 24
Level 24
Posts: 22176
Joined: Wed Jul 06, 2011 3:58 am
Location: The Netherlands

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by xenopeek » Tue Jan 09, 2018 1:42 pm

I think that's pointless. Just use a browser with mitigation and move on. There are no tangible threats out there and these bugs are not trivial to exploit.

BTW, LMDE 2 has just received kernel 3.16.51-3+deb8u1 which fixes variant 3 (Meltdown).
Image

Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Tue Jan 09, 2018 1:51 pm

Sure, that's good to hear, thank you!
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Tue Jan 09, 2018 2:26 pm

Security notice: Meltdown and Spectre
https://blog.linuxmint.com/?p=3496
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

User avatar
karlchen
Level 18
Level 18
Posts: 8647
Joined: Sat Dec 31, 2011 7:21 am
Location: Germany

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by karlchen » Tue Jan 09, 2018 7:41 pm

Question:
Has anyone received the promised security updates for Meltdown?
Answer:
Yes, those security updates which match the software installed on my Linux Mint 18.1 Cinnamon 64-bit.

Kernel:

Code: Select all

$ uname -a
Linux voyager 4.4.0-109-generic #132-Ubuntu SMP Tue Jan 9 19:52:39 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux
Firefox:

Code: Select all

$ dpkg --list firefox | grep "^ii"
ii  firefox        57.0.4+build1-0ubuntu0.16.04.1 amd64        Safe and easy web browser from Mozilla
Last edited by karlchen on Wed Jan 10, 2018 7:02 pm, edited 1 time in total.
Reason: Replaced K4.4.0-108 kernel info (09.01.2017) by (bugfixed) K4.4.0-109 kernel info (10.01.2018)
Image
Old bugs good, new bugs bad! Updates are evil: might fix old bugs and introduce no new ones.

Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Tue Jan 09, 2018 8:19 pm

But KPTI patches for 4.13, not yet?
Last edited by Marziano on Tue Jan 09, 2018 9:15 pm, edited 1 time in total.
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

User avatar
Schultz
Level 6
Level 6
Posts: 1140
Joined: Thu Feb 25, 2016 8:57 pm

Re: January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Schultz » Tue Jan 09, 2018 8:23 pm

So they released a new 4.4 kernel? I've gotten nothing yet for 4.13. :?:

Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

[SOLVED] January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Tue Jan 09, 2018 11:05 pm

Schultz wrote:So they released a new 4.4 kernel? I've gotten nothing yet for 4.13. :?:
Good news! The long awaited kernel update for 4.13 is finally there!
cheers
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

User avatar
karlchen
Level 18
Level 18
Posts: 8647
Joined: Sat Dec 31, 2011 7:21 am
Location: Germany

Re: [SOLVED]January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by karlchen » Wed Jan 10, 2018 2:22 pm

Oh, I am so excited.
Last night I received the security for my kernel K4.4.0-108(131).
This evening I received the bugfix for the security fix, kernel K4.4.0-109(132).
I cannot tell how much I am looking forward to tomorrow's kernel security or bugfix or maybe even a combination of both.
I love daily kernel updates. :lol:
--
Seriously: I do really appreciate that the Ubuntu people found and corrected their mistake within 24 hours.
Image
Old bugs good, new bugs bad! Updates are evil: might fix old bugs and introduce no new ones.

Marziano
Level 6
Level 6
Posts: 1211
Joined: Thu Jan 04, 2018 1:00 pm

Re: [SOLVED]January 9, 2018: Has anyone received the promised security updates for Meltdown?

Post by Marziano » Wed Jan 10, 2018 2:38 pm

I was terrified before for even mentioning the kernel, now it seems that I can't get enough of them. Just bring them on :!:
"Those are my principles, and if you don't like them...well, I have others." -Marx...
Groucho { Marx

Post Reply

Return to “Open chat”