& cplSiteName &

Intel: We've Patched Most Chips for 'Spectre' & 'Meltdown'

Mitch Wagner

Intel will have patches issued by next week to protect more than 90% of its processors introduced in the last five years, in the wake of disclosure of serious security vulnerabilities affecting nearly every computer user in the world.

In a statement Thursday, Intel Corp. (Nasdaq: INTC) says it is rapidly rolling out updates for personal computers and servers based on its processors "that render those systems immune" to the Spectre and Meltdown security vulnerabilities reported this week. Those vulnerabilities can allow attackers to gain access to a computer's memory, reaping passwords and other confidential information. The vulnerabilities affect virtually every Intel-based system in the world. (See New Intel Vulnerability Hits Almost Everyone.)

More specifically, Meltdown affects virtually every Intel processor made since 1995, and Spectre affects Intel, AMD and ARM processors, according to a statement from researchers.

"Intel has already issued updates for the majority of processor products introduced within the past five years," Intel says. "By the end of next week, Intel expects to have issued updates for more than 90 percent of processor products introduced within the past five years. In addition, many operating system vendors, public cloud service providers, device manufacturers and others have indicated that they have already updated their products and services." (See Intel Chip Vulnerability Sends Cloud Providers Into Patching Overdrive.)

But can Spectre be so easily beaten? The research paper describing the vulnerability suggest a permanent fix is a major undertaking: "While makeshift processor-specific countermeasures are possible in some cases, sound solutions will require fixes to processor designs as well as updates to instruction set architectures (ISAs) to give hardware architects and software developers a common understanding as to what computation state CPU implementations are (and are not) permitted to leak."

However, Intel stands by its fix. "With regard to Intel’s products, all the issues disclosed by researchers can be mitigated either by software or firmware updates. That includes both Meltdown and Spectre," a company spokesperson said in an email statement.

Keep up with the latest enterprise cloud news and insights. Sign up for the weekly Enterprise Cloud News newsletter.

Intel also pushed back on claims that the patches would slow system performance by 20% to 30%. "Intel continues to believe that the performance impact of these updates is highly workload-dependent and, for the average computer user, should not be significant and will be mitigated over time. While on some discrete workloads the performance impact from the software updates may initially be higher, additional post-deployment identification, testing and improvement of the software updates should mitigate that impact," the company said.

We've asked infrastructure suppliers on how their products and customers are impacted, and mostly they still seem to be figuring it out. VMware Inc. (NYSE: VMW) has patches available for its vSphere ESXi, Workstation Pro and Fusion Pro products.

Microsoft Corp. (Nasdaq: MSFT) has patches available for Windows desktops and servers, as well as SQL Server, and says it has "already deployed mitigations across the majority of our cloud services and is accelerating efforts to complete the remainder."

Cisco Systems Inc. (Nasdaq: CSCO) issued a statement Thursday afternoon, saying most of its products are not vulnerable. "Although the underlying CPU and OS combination in a product may be affected by these vulnerabilities, the majority of Cisco products are closed systems that do not allow customers to run custom code on the device, and thus are not vulnerable," the company said. Only Cisco devices that allow customers to "execute their customized code side-by-side with the Cisco code on the same microprocessor are considered vulnerable," said Cisco.

Also, Cisco products that can be deployed as virtual machines or containers could be targeted by attacks "if the hosting environment is vulnerable. Cisco recommends customers to harden their virtual environment and to ensure that all security updates are installed," the company said, adding that it plans to release software updates to address the vulnerability.

Related posts:

— Mitch Wagner Follow me on Twitter Visit my LinkedIn profile Visit my blog Follow me on Facebook Editor, Enterprise Cloud News

(19)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Educational Resources
sponsor supplied content
Educational Resources Archive
More Blogs from Wagner’s Ring
Platform is designed to enable enterprises to build big data analytics apps that move easily between public and private clouds.
Buying Evident.io extends Palo Alto's portfolio with API-based security capabilities and compliance automation.
Google wants to win the hearts of enterprise IT for Chrome OS on the desktop, but it has a long way to go.
IBM Cloud gets a security and Kubernetes performance boost.
Atlassian moved its Jira and Confluence developer collaboration tools to Amazon Web Services.
Featured Video
From The Founder
Ngena's global 'network of networks' solves a problem that the telecom vendors promised us would never exist. That doesn't mean its new service isn't a really good idea.
Flash Poll
Upcoming Live Events
March 28, 2018, Kansas City Convention Center
April 4, 2018, The Westin Dallas Downtown, Dallas
April 9, 2018, Las Vegas Convention Center
May 14-16, 2018, Austin Convention Center
May 14, 2018, Brazos Hall, Austin, Texas
September 24-26, 2018, Westin Westminster, Denver
October 9, 2018, The Westin Times Square, New York
October 23, 2018, Georgia World Congress Centre, Atlanta, GA
November 7-8, 2018, London, United Kingdom
November 8, 2018, The Montcalm by Marble Arch, London
November 15, 2018, The Westin Times Square, New York
December 4-6, 2018, Lisbon, Portugal
All Upcoming Live Events
Hot Topics
Dell CTO: Public Cloud Is 'Way More Expensive Than Buying From Us'
Mitch Wagner, Mitch Wagner, Editor, Enterprise Cloud, Light Reading, 3/19/2018
Eurobites: Cambridge Analytica Feels the Heat
Paul Rainford, Assistant Editor, Europe, 3/20/2018
Is Business Voice Rapidly Fading?
Carol Wilson, Editor-at-large, 3/15/2018
HR: Cable Dominates US Broadband
Carol Wilson, Editor-at-large, 3/21/2018
Animals with Phones
Live Digital Audio

A CSP's digital transformation involves so much more than technology. Crucial – and often most challenging – is the cultural transformation that goes along with it. As Sigma's Chief Technology Officer, Catherine Michel has extensive experience with technology as she leads the company's entire product portfolio and strategy. But she's also no stranger to merging technology and culture, having taken a company — Tribold — from inception to acquisition (by Sigma in 2013), and she continues to advise service providers on how to drive their own transformations. This impressive female leader and vocal advocate for other women in the industry will join Women in Comms for a live radio show to discuss all things digital transformation, including the cultural transformation that goes along with it.

Like Us on Facebook
Twitter Feed