10 ms·
Just received a message from Rackspace cloud regarding theses, it seems like they will have to reboot all instances. See https://community.rackspace.com/genera
by j15e 12y ago
Just received a message from Rackspace cloud regarding theses, it seems like they will have to reboot all instances.
See https://community.rackspace.com/general/f/53/t/4978 https://community.rackspace.com/general/f/53/t/4978
- cvuletich 12y agoSee ya later uptime... 04:49:58 up 659 days
- rgbrenner 12y agoSee ya later uptime... 04:49:58 up 659 days your server is vulnerable to a number of Xen security vulnerabilities: http://xenbits.xen.org/xsa/ http://xenbits.xen.org/xsa/ Including this one from Oct 1, 2014 that allows guests to read up to 3KB of memory from the hypervisor or other guests: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188 http://threatpost.com/serious-hypervisor-bug-fix-causes-unexpected-cloud-downtime/108660 http://threatpost.com/serious-hypervisor-bug-fix-causes-unex...
- singlow 12y agoYeah. I had one server with over 900 days prior to Oct. It probably should have been rebooted for other reasons but thats the one that forced it.
- mnordhoff 12y agoThat vulnerability only applies to HVM guests. No doubt there are other reasons to have rebooted since 2013, but if one of Rackspace's servers only has paravirtualized guests (do they use HVM at all? I don't know), they can get by without patching it.
- deleted 12y ago[deleted]
- rgbrenner 12y agoDid you see how many vulnerabilities 659 days covers? I mean, if that one doesn't apply, just go back a bit. How about this one from June 2014: memory pages that were in use by the hypervisor and are eligible to be allocated to guests weren't being properly cleaned. Such exposure of information would happen through memory pages freshly allocated to or by the guest. ... it is possible for an attacker to obtain modest amounts of in-flight and in-use data, which might contain passwords or cryptographic keys. http://xenbits.xen.org/xsa/advisory-100.html http://xenbits.xen.org/xsa/advisory-100.html
- kbar13 12y agorackspace most likely uses hvm guests. I think they had freebsd before there was xen pv support
- yclept 12y agoRackspace has both HV and PV for most default linux images
- zatkin 12y agoOuch! Might I ask what datacentre you're using?
- spaam 12y agoi had something similar at linode london.
- e12e 12y agoIs that a guest or a host? If it's a guest, there shouldn't be a need for reboot, only suspend/resume... (note that a reboot can be a good idea from time to time, just to make sure the current configuration (eg: post kernel upgrades, before reboot) -- actually boots).
- ryan-c 12y agoprgmr did reboots yesterday
- plq 12y agoYet linode is still silent...
- kbar13 12y agorealize that there's Xen HVM and Xen PV. there have been significantly more security issues in HVM than there have been in PV.
- walterbell 12y agoDo we know why HVM/hw-virt has had more security issues than PV/sw-virt?
- larsk 12y agoYes, because it uses QEMU. That means more code, and ultimately more bugs, which means more possible exploits.
- KenCochrane 12y agoI got an email from linode yesterday telling me they need to do the same. Not sure if they had any public communication yet.
- paulrosenzweig 12y agoLinode rebooted my server in Tokyo ~16 hours ago.
- jedicoffee 12y agohttp://status.linode.com/incidents/2dyvn29ds5mz http://status.linode.com/incidents/2dyvn29ds5mz