adoptium / infrastructure

This repo contains all information about machine maintenance.
Apache License 2.0
86 stars 101 forks source link

update/security: Upgrade kernel on scaleway machines #3719

Open luhenry opened 2 months ago

luhenry commented 2 months ago

With the recent GhostWrite attack, we need to update the kernels on our RISC-V machines hosted at Scaleway. The steps are documented at https://www.scaleway.com/en/docs/bare-metal/elastic-metal/reference-content/elastic-metal-rv1-guidelines/#update-the-kernel

That kernel update will also allow to disable completely the support for vector on these machines, both for security reasons (as it's the source of the attack in question), but also because the vector instructions available on this machines implement an unratified version of the Vector spec (not 1.0.0).

cc @sxa

Haroon-Khel commented 2 months ago

To reiterate, in the scaleway console the Eclipse Adoptium user is not able to access the more info page of the test-rise machines to be able to boot them into rescue mode. Awaiting the required permissions