AMD & Spectre

Chat about anything related to Linux Mint
Post Reply
benchrest
Level 1
Level 1
Posts: 48
Joined: Tue Jan 17, 2012 2:19 pm

AMD & Spectre

Post by benchrest » Mon Jan 22, 2018 12:39 pm

I am frustrated by the information I have been able to find on this subject. I feel installing some of the fixes for this flaw are a greater risk than the flaw itself.
I have a AMD FX-4100 on an ASUS M5A97 R2.0 MB.
No where have I been able to find comprehensive information on resolving the issue. I have Firefox 57.0.4 which I think should give me some protection from bad websites.
LM last update on the bug is 1/9, but I am not even sure LM should be the one giving an update. But since AMD only acknowledged they had a problem after 1/9 that info cannot be current.
ASUS web site gives no info and the latest BIOS for my MB is 2603 dated 9/24/15 . I think that even with a kernel update I still need a BIOS update to fully resolve this issue.
So I am sitting on installing 4.13.0-26 and NVIDIA 340.104 . Hesitant to install yet not sure. 4.13.0-26 came out before AMD acknowledged they had a problem with Spectre. So can it possibly protect my computer?
I wish I could find a web site with daily updates of the latest status of patches for the Spectre flaw.
Rich
LM Cinnamon 18.1, ASUS M5A97 R2.0 MB, FX-4100, Samsung SSD 850 Pro 256gb, dual 23" monitors. Big user of Gramps, L.O., Unison, Synapse. Entire system on SSD, also WD black 500gb..

User avatar
xenopeek
Level 24
Level 24
Posts: 21798
Joined: Wed Jul 06, 2011 3:58 am
Location: The Netherlands

Re: AMD & Spectre

Post by xenopeek » Mon Jan 22, 2018 2:12 pm

You can use this script https://github.com/speed47/spectre-meltdown-checker to check status of your system. Download it and run the included spectre-meltdown-checker.sh file as root. From the directory where you have extracted or saved that file, you do that on the terminal with command:
sudo sh spectre-meltdown-checker.sh

If you installed the available security updates for your kernel, you have the fix for Meltdown.

You can check if your web browser is vulnerable with this: https://xlab.tencent.com/special/spectr ... check.html. Firefox 57.0.4 has mitigation in place so that websites can't use the Meltdown and Spectre bugs. Do you use any other programs that run untrusted code on your system? For most home users the answer is no and they are thus not exposed to any malware that would use the Spectre bugs.

There is no security update for the kernel available yet that addresses Spectre. You can follow the progress of the security team on that here: https://wiki.ubuntu.com/SecurityTeam/Kn ... ndMeltdown. But again: check your web browser if it's not Firefox and confirm it's not vulnerable to Meltdown and Spectre. For most home users that closes the door on these bugs already. Unless you're in the habit of downloading and installing programs onto your system from untrusted websites.
Image

Post Reply

Return to “Chat about Linux Mint”