Spectre V2 : System may be vulnerable to spectre v2

Bug #1748470 reported by Cristian Aravena Romero
22
This bug affects 5 people
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Triaged
High
Unassigned

Bug Description

Hello,

dmesg:
[ 1813.660535] vboxdrv: loading out-of-tree module taints kernel.
[ 1813.660542] Spectre V2 : System may be vulnerable to spectre v2
[ 1813.660552] vboxdrv: loading module not compiled with retpoline compiler.
[ 1813.661206] vboxdrv: module verification failed: signature and/or required key missing - tainting kernel
[ 1813.680341] vboxdrv: Found 4 processor cores
[ 1813.697413] vboxdrv: TSC mode is Invariant, tentative frequency 1496590422 Hz
[ 1813.697415] vboxdrv: Successfully loaded version 5.2.6_Ubuntu (interface 0x00290000)
[ 1813.706824] Spectre V2 : System may be vulnerable to spectre v2
[ 1813.706832] vboxnetflt: loading module not compiled with retpoline compiler.
[ 1813.707367] VBoxNetFlt: Successfully started.
[ 1813.716935] Spectre V2 : System may be vulnerable to spectre v2
[ 1813.716943] vboxnetadp: loading module not compiled with retpoline compiler.
[ 1813.718033] VBoxNetAdp: Successfully started.
[ 1813.730511] Spectre V2 : System may be vulnerable to spectre v2
[ 1813.730518] vboxpci: loading module not compiled with retpoline compiler.
[ 1813.731043] VBoxPciLinuxInit
[ 1813.735258] vboxpci: IOMMU not found (not registered)
[ 1818.059815] VBoxPciLinuxLinuxUnload
[ 1818.182382] Spectre V2 : System may be vulnerable to spectre v2
[ 1818.182394] vboxdrv: loading module not compiled with retpoline compiler.
[ 1818.203403] vboxdrv: Found 4 processor cores
[ 1818.225454] vboxdrv: TSC mode is Invariant, tentative frequency 1496570131 Hz
[ 1818.225457] vboxdrv: Successfully loaded version 5.2.6_Ubuntu (interface 0x00290000)
[ 1818.239394] Spectre V2 : System may be vulnerable to spectre v2
[ 1818.239403] vboxnetflt: loading module not compiled with retpoline compiler.
[ 1818.240180] VBoxNetFlt: Successfully started.
[ 1818.251133] Spectre V2 : System may be vulnerable to spectre v2
[ 1818.251143] vboxnetadp: loading module not compiled with retpoline compiler.
[ 1818.251726] VBoxNetAdp: Successfully started.
[ 1818.263523] Spectre V2 : System may be vulnerable to spectre v2
[ 1818.263530] vboxpci: loading module not compiled with retpoline compiler.
[ 1818.264039] VBoxPciLinuxInit
[ 1818.266382] vboxpci: IOMMU not found (not registered)
[ 1857.952441] SUPR0GipMap: fGetGipCpu=0xb
[ 1859.046216] vboxdrv: 0000000000000000 VMMR0.r0
[ 1859.301126] vboxdrv: 0000000000000000 VBoxDDR0.r0

Regards,
--
Cristian

ProblemType: Bug
DistroRelease: Ubuntu 18.04
Package: linux-image-4.15.0-9-generic 4.15.0-9.10
ProcVersionSignature: Ubuntu 4.15.0-9.10-generic 4.15.2
Uname: Linux 4.15.0-9-generic x86_64
ApportVersion: 2.20.8-0ubuntu8
Architecture: amd64
AudioDevicesInUse:
 USER PID ACCESS COMMAND
 /dev/snd/pcmC0D0p: caravena 1849 F...m pulseaudio
 /dev/snd/controlC0: caravena 1849 F.... pulseaudio
CurrentDesktop: ubuntu-communitheme:ubuntu:GNOME
Date: Fri Feb 9 13:07:10 2018
InstallationDate: Installed on 2017-10-13 (119 days ago)
InstallationMedia: Ubuntu 17.10 "Artful Aardvark" - Alpha amd64 (20170926)
MachineType: SAMSUNG ELECTRONICS CO., LTD. 530U3C/530U4C
ProcFB: 0 inteldrmfb
ProcKernelCmdLine: BOOT_IMAGE=/@/boot/vmlinuz-4.15.0-9-generic root=UUID=707d0f89-4b1d-4432-9d50-6058dc4c1ee9 ro rootflags=subvol=@ quiet splash vt.handoff=1
RelatedPackageVersions:
 linux-restricted-modules-4.15.0-9-generic N/A
 linux-backports-modules-4.15.0-9-generic N/A
 linux-firmware 1.170
SourcePackage: linux
UpgradeStatus: No upgrade log present (probably fresh install)
dmi.bios.date: 04/15/2013
dmi.bios.vendor: Phoenix Technologies Ltd.
dmi.bios.version: P14AAJ
dmi.board.asset.tag: Base Board Asset Tag
dmi.board.name: SAMSUNG_NP1234567890
dmi.board.vendor: SAMSUNG ELECTRONICS CO., LTD.
dmi.board.version: FAB1
dmi.chassis.asset.tag: No Asset Tag
dmi.chassis.type: 9
dmi.chassis.vendor: SAMSUNG ELECTRONICS CO., LTD.
dmi.chassis.version: 0.1
dmi.modalias: dmi:bvnPhoenixTechnologiesLtd.:bvrP14AAJ:bd04/15/2013:svnSAMSUNGELECTRONICSCO.,LTD.:pn530U3C/530U4C:pvr0.1:rvnSAMSUNGELECTRONICSCO.,LTD.:rnSAMSUNG_NP1234567890:rvrFAB1:cvnSAMSUNGELECTRONICSCO.,LTD.:ct9:cvr0.1:
dmi.product.family: ChiefRiver System
dmi.product.name: 530U3C/530U4C
dmi.product.version: 0.1
dmi.sys.vendor: SAMSUNG ELECTRONICS CO., LTD.
---
ApportVersion: 2.20.8-0ubuntu10
Architecture: amd64
AudioDevicesInUse:
 USER PID ACCESS COMMAND
 /dev/snd/pcmC0D0p: caravena 1797 F...m pulseaudio
 /dev/snd/controlC0: caravena 1797 F.... pulseaudio
CurrentDesktop: ubuntu-communitheme:ubuntu:GNOME
DistroRelease: Ubuntu 18.04
InstallationDate: Installed on 2017-10-13 (123 days ago)
InstallationMedia: Ubuntu 17.10 "Artful Aardvark" - Alpha amd64 (20170926)
MachineType: SAMSUNG ELECTRONICS CO., LTD. 530U3C/530U4C
Package: linux (not installed)
ProcFB: 0 inteldrmfb
ProcKernelCmdLine: BOOT_IMAGE=/@/boot/vmlinuz-4.15.0-10-generic root=UUID=707d0f89-4b1d-4432-9d50-6058dc4c1ee9 ro rootflags=subvol=@ quiet splash vt.handoff=1
ProcVersionSignature: Ubuntu 4.15.0-10.11-generic 4.15.3
RelatedPackageVersions:
 linux-restricted-modules-4.15.0-10-generic N/A
 linux-backports-modules-4.15.0-10-generic N/A
 linux-firmware 1.170
Tags: bionic
Uname: Linux 4.15.0-10-generic x86_64
UpgradeStatus: No upgrade log present (probably fresh install)
UserGroups: adm cdrom dialout dip libvirt lpadmin plugdev sambashare sudo
_MarkForUpload: True
dmi.bios.date: 04/15/2013
dmi.bios.vendor: Phoenix Technologies Ltd.
dmi.bios.version: P14AAJ
dmi.board.asset.tag: Base Board Asset Tag
dmi.board.name: SAMSUNG_NP1234567890
dmi.board.vendor: SAMSUNG ELECTRONICS CO., LTD.
dmi.board.version: FAB1
dmi.chassis.asset.tag: No Asset Tag
dmi.chassis.type: 9
dmi.chassis.vendor: SAMSUNG ELECTRONICS CO., LTD.
dmi.chassis.version: 0.1
dmi.modalias: dmi:bvnPhoenixTechnologiesLtd.:bvrP14AAJ:bd04/15/2013:svnSAMSUNGELECTRONICSCO.,LTD.:pn530U3C/530U4C:pvr0.1:rvnSAMSUNGELECTRONICSCO.,LTD.:rnSAMSUNG_NP1234567890:rvrFAB1:cvnSAMSUNGELECTRONICSCO.,LTD.:ct9:cvr0.1:
dmi.product.family: ChiefRiver System
dmi.product.name: 530U3C/530U4C
dmi.product.version: 0.1
dmi.sys.vendor: SAMSUNG ELECTRONICS CO., LTD.

Revision history for this message
Cristian Aravena Romero (caravena) wrote :
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Status changed to Confirmed

This change was made by a bot.

Changed in linux (Ubuntu):
status: New → Confirmed
Changed in linux (Ubuntu):
importance: Undecided → High
status: Confirmed → Triaged
tags: added: pti
Revision history for this message
Cristian Aravena Romero (caravena) wrote : AlsaInfo.txt

apport information

tags: added: apport-collected
description: updated
Revision history for this message
Cristian Aravena Romero (caravena) wrote : CRDA.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : CurrentDmesg.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : IwConfig.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : JournalErrors.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : Lspci.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : Lsusb.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : ProcCpuinfo.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : ProcCpuinfoMinimal.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : ProcEnviron.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : ProcInterrupts.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : ProcModules.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : PulseList.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : RfKill.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : UdevDb.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote : WifiSyslog.txt

apport information

Revision history for this message
Cristian Aravena Romero (caravena) wrote :

Hello,

* Ubuntu 4.15.0-10.11-generic 4.15.3
* The VirtualBox message is no longer

dmesg:
[ 19.054411] vboxdrv: loading out-of-tree module taints kernel.
[ 19.054732] vboxdrv: module verification failed: signature and/or required key missing - tainting kernel
[ 19.070696] vboxdrv: Found 4 processor cores
[ 19.096198] vboxdrv: TSC mode is Invariant, tentative frequency 1496599865 Hz
[ 19.096200] vboxdrv: Successfully loaded version 5.2.6_Ubuntu (interface 0x00290000)
[ 19.458556] VBoxNetFlt: Successfully started.
[ 19.861542] VBoxNetAdp: Successfully started.
[ 19.880738] VBoxPciLinuxInit
[ 19.909522] vboxpci: IOMMU not found (not registered)

Regards,
--
Cristian

Revision history for this message
Joseph Salisbury (jsalisbury) wrote :

Sorry I missed your message on IRC. Thanks for the report, Cristian. I have tagged the bug with 'pti'. This will ensure it is reviewed with all of the other spectre mitigation bugs.

We are still working to address all of the spectre vulnerabilities.

One way to tell the current level of your system is with this command:
tail /sys/devices/system/cpu/vulnerabilities/*

tags: added: kernel-da-key
Revision history for this message
Cristian Aravena Romero (caravena) wrote :

Hello Joseph,

Thanks for you work :-)

Linux version: Ubuntu 4.15.0-10.11-generic 4.15.3

$tail /sys/devices/system/cpu/vulnerabilities/*
==> /sys/devices/system/cpu/vulnerabilities/meltdown <==
Mitigation: PTI

==> /sys/devices/system/cpu/vulnerabilities/spectre_v1 <==
Mitigation: __user pointer sanitization

==> /sys/devices/system/cpu/vulnerabilities/spectre_v2 <==
Mitigation: Full generic retpoline

Regards,
--
Cristian

Revision history for this message
Lee (lee48) wrote :

user@server2:~$ tail /sys/devices/system/cpu/vulnerabilities/*
==> /sys/devices/system/cpu/vulnerabilities/meltdown <==
Mitigation: PTI

==> /sys/devices/system/cpu/vulnerabilities/spectre_v1 <==
Mitigation: __user pointer sanitization

==> /sys/devices/system/cpu/vulnerabilities/spectre_v2 <==
Mitigation: Full generic retpoline - vulnerable module loaded

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.