Linus Torvalds says Retbleed has been addressed in the Linux kernel, but code complexity means the release will be delayed by a week to give more time for testing. . Linux kernel developers have successfully addressed Retbleed, the latest Spectre-like speculative execution attack against older AMD and Intel processors, Linus Torvalds wrote in a message to the Linux Kernel Mailing List on Sunday. However, the difficult repair process means there will be a delay of the release for Linux version 5.19 by a week. "I think we've got the retbleed fallout all handled (knock wood)," Torvalds wrote . The complexity of the fix wasn't the only reason for the release; there were two other development trees that independently asked for an extension. The other trees that needed the extension involve the btrfs filesystems and firmware for Intel GPU controllers. . Kernel engineers successfully addressed the Retbleed issue but postponed the release for additional testing because of the intricate nature of the fixes and additional components required.. Retbleed Fix, Linux Kernel Update, Speculative Attack Mitigation. . Brittany Day
Cybersecurity researchers have identified two new vulnerabilities in Linux-based OSes that, if successfully exploited, could enable attackers to bypass mitigations for speculative attacks such as Spectre and obtain sensitive information from kernel memory. . Discovered by Piotr Krysiuk of Symantec's Threat Hunter team, the flaws — tracked as CVE-2020-27170 and CVE-2020-27171 (CVSS scores: 5.5) — impact all Linux kernels prior to 5.11.8. Patches for the security issues were released on March 20, with Ubuntu, Debian, and Red Hat deploying fixes for the vulnerabilities in their respective Linux distributions. While CVE-2020-27170 can be abused to reveal content from any location within the kernel memory, CVE-2020-27171 can be used to retrieve data from a 4GB range of kernel memory. The link for this article located at The Hacker News is no longer available. . Newly discovered weaknesses could enable cybercriminals to circumvent Spectre defenses on Linux platforms, raising issues of data privacy.. Linux Kernel Security,Spectre Attack,Kernel Mitigation Bypass,Red Hat Fix. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.