Tag Archives: kernel

Is a retpoline-enabled kernel ‘enough’ to fully protect against Spectre Variant 2?

The Spectre attack exposed processors to memory disclosure attacks. Manipulation of indirect kernel calls may allow side channel retrieval of memory content (Branch Target Injection). The Linux kernel was subsequently enhanced to mitigate this Variant II attack using the retpoline … Continue reading

Posted in Uncategorised | Tagged , , , , | Comments Off on Is a retpoline-enabled kernel ‘enough’ to fully protect against Spectre Variant 2?

CVE-2018-5390 Linux Kernel TCP implementation vulnerable to Denial of Service

News of a new vulnerability in the Linux kernel is worth reviewing (https://www.kb.cert.org/vuls/id/962459). The vulnerability affects kernels 4.9 and later, and can apparently be exploited by a remote attacker interacting with an open port. Patches are available.

Posted in Uncategorised | Tagged , , , , , | Comments Off on CVE-2018-5390 Linux Kernel TCP implementation vulnerable to Denial of Service