[Whonix-devel] [Oracle VM VirtualBox] #17987: VirtualBox 5.2.18 vulnerable to spectre/meltdown despite microcode being installed

Oracle VM VirtualBox trac at virtualbox.org
Fri Sep 14 15:26:51 CEST 2018


#17987: VirtualBox 5.2.18 vulnerable to spectre/meltdown despite microcode being
installed
-------------------------------+--------------------------------------------
 Reporter:  adrelanos          |        Owner:          
     Type:  defect             |       Status:  reopened
 Priority:  major              |    Component:  other   
  Version:  VirtualBox 5.2.18  |   Resolution:          
 Keywords:                     |   Guest type:  Linux   
Host type:  Linux              |  
-------------------------------+--------------------------------------------

Comment (by adrelanos):

 Will provide soon.

 Updated, full list of settings tried to fix this.

 {{{
 VBoxManage modifyvm vm-name --ibpb-on-vm-entry on
 VBoxManage modifyvm vm-name --ibpb-on-vm-exit on
 VBoxManage modifyvm vm-name --l1d-flush-on-vm-entry on
 VBoxManage modifyvm vm-name --l1d-flush-on-sched on
 VBoxManage modifyvm vm-name --spec-ctrl on
 VBoxManage modifyvm vm-name --nestedpaging off
 }}}

 (sudo spectre-meltdown-checker --paranoid ; echo $? still exists non-zero
 and shows "vulnerable".)

-- 
Ticket URL: <https://www.virtualbox.org/ticket/17987#comment:5>
Oracle VM VirtualBox <https://www.virtualbox.org/>


More information about the Whonix-devel mailing list