From: Paolo Bonzini <pbonzini@redhat.com>
To: Stefan Priebe - Profihost AG <s.priebe@profihost.ag>,
Alexandre DERUMIER <aderumier@odiso.com>
Cc: qemu-devel <qemu-devel@nongnu.org>
Subject: Re: [Qemu-devel] CVE-2017-5715: relevant qemu patches
Date: Fri, 5 Jan 2018 09:33:04 +0100 [thread overview]
Message-ID: <24204049-c489-df35-3775-ee5121e13f0f@redhat.com> (raw)
In-Reply-To: <b3231ee0-a232-057b-dbfe-bd31e0d4bf02@profihost.ag>
On 04/01/2018 21:15, Stefan Priebe - Profihost AG wrote:
> attached the relevant patch for everybody who needs it.
This is the original patch from Intel, which doesn't work unless you
have a patched kernel (which you almost certainly don't have) and
doesn't even warn you about that.
In other words, it's rubbish. Please read
https://www.qemu.org/2018/01/04/spectre/ several times, until you
understand why there is no urgent need to update QEMU.
Days are 24 hours for QEMU developers just like for you (and believe me,
we wished several times that they weren't during the last two months).
We are prioritizing the fixes according to their effect in mitigating
the vulnerability, their applicability and the availability of patches
to the lower levels of the stack. Right now, the most urgent part is
the simple mitigations that can go in Linux 4.15 and stable kernels.
Paolo
next prev parent reply other threads:[~2018-01-05 8:33 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-01-04 6:27 [Qemu-devel] CVE-2017-5715: relevant qemu patches Stefan Priebe - Profihost AG
2018-01-04 7:24 ` Alexandre DERUMIER
2018-01-04 7:27 ` Alexandre DERUMIER
2018-01-04 8:17 ` Stefan Priebe - Profihost AG
2018-01-04 8:35 ` Alexandre DERUMIER
2018-01-04 9:22 ` Stefan Priebe - Profihost AG
2018-01-04 15:53 ` Paolo Bonzini
2018-01-04 20:15 ` Stefan Priebe - Profihost AG
2018-01-05 8:33 ` Paolo Bonzini [this message]
2018-01-05 10:40 ` Stefan Priebe - Profihost AG
2018-01-05 10:57 ` Paolo Bonzini
2018-01-04 12:53 ` Stefan Priebe - Profihost AG
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=24204049-c489-df35-3775-ee5121e13f0f@redhat.com \
--to=pbonzini@redhat.com \
--cc=aderumier@odiso.com \
--cc=qemu-devel@nongnu.org \
--cc=s.priebe@profihost.ag \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).