--Apple-Mail=_78F19FC9-4529-459D-8AFF-F81CDA40E6C7
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
On 4 Jan 2018, at 22:16, Sandro Bonazzola <sbonazzo(a)redhat.com>
wrote:
=20
=20
=20
2018-01-04 17:21 GMT+01:00 Yaniv Kaul <ykaul(a)redhat.com =
<mailto:ykaul@redhat.com>>:
=20
=20
On Thu, Jan 4, 2018 at 12:31 PM, Barak Korren <bkorren(a)redhat.com =
<mailto:bkorren@redhat.com>> wrote:
On 4 January 2018 at 09:24, Marcel Hanke <marcel.hanke(a)1und1.de =
<mailto:marcel.hanke@1und1.de>> wrote:
> Hi,
> besides the kernel and microcode updates are there also updates of =
ovirt-
> engine and vdsm nessessary and if so, is there a timeline when
the =
patches can
> be expected?
yes there are
right after the base OS is completely covered
> If there are Patches nessessary will there also be updates for
ovirt =
4.1 or
> only 4.2?
4.1 will be covered
=20
Looking at the relevant Red Hat announcement:
=
https://access.redhat.com/security/vulnerabilities/speculativeexecution =
<
https://access.redhat.com/security/vulnerabilities/speculativeexecution>
=20
It seems that no packages that are derived directly from oVirt were =
updated.
they are, the page is updating as it progresses
You can see qemu-kvm-rhev there, which is quemu-kvm-ev in CentOS -
that used to be distributed by oVirt, but these days its is shipped as
part of the CentOS VirtSIG repo.
=20
AFAIK none of those components were released on CentOS yet, so if
you're running oVirt on CentOS you'll need to wait.
=20
CentOS kernel, microcode_ctl and linux-firmware have been released.
See [1] for example. I'm sure others will follow.
Y.
=20
[1] =
https://lists.centos.org/pipermail/centos-announce/2018-January/022696.htm=
l =
<
https://lists.centos.org/pipermail/centos-announce/2018-January/022696.ht=
ml>
=20
=20
qemu-kvm-ev has also been tagged for release, will be in next batch or =
earlier if
I can find kbsing for manually push it.
=20
=20
=20
=20
=20
I suppose oVirt packages and install scripts will be updated over the
next few days to require the newer packages, but you do not need to
wait for those updates to patch your systems, you can probably patch
as soon as the updates are made available.
I suggest to start with the kernel
But please do read up on the various variants and mitigations. You may =
not necessarily need all of them
Also, you may lack the right firmware/microcode updates from your CPU =
vendor at the moment. Red Hat's microcode package only contains those =
which were released by Intel/AMD so far.
Thanks,
michal
=20
Once updates are available, a new node and engine-apppliance images
will probably also be built and released.
=20
Please note that the above as mostly a rough estimate based on my
familiarity with the processes involved, I am not directly affiliated
with any of the teams handling the response to these CVEs.
=20
--
Barak Korren
RHV DevOps team , RHCE, RHCi
Red Hat EMEA
redhat.com <
http://redhat.com/> | TRIED. TESTED. TRUSTED. | =
redhat.com/trusted <
http://redhat.com/trusted>
_______________________________________________
Users mailing list
Users(a)ovirt.org <mailto:Users@ovirt.org>
http://lists.ovirt.org/mailman/listinfo/users =
<
http://lists.ovirt.org/mailman/listinfo/users>
>=20
>=20
_______________________________________________
Users mailing list
Users(a)ovirt.org <mailto:Users@ovirt.org>
http://lists.ovirt.org/mailman/listinfo/users =
<
http://lists.ovirt.org/mailman/listinfo/users>
=20
=20
=20
=20
--=20
SANDRO BONAZZOLA
ASSOCIATE MANAGER, SOFTWARE ENGINEERING, EMEA ENG VIRTUALIZATION R&D
Red Hat=C2=A0EMEA <
https://www.redhat.com/>
<
https://red.ht/sig>=09
TRIED. TESTED. TRUSTED. <
https://redhat.com/trusted>
_______________________________________________
Users mailing list
Users(a)ovirt.org
http://lists.ovirt.org/mailman/listinfo/users
--Apple-Mail=_78F19FC9-4529-459D-8AFF-F81CDA40E6C7
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
charset=us-ascii
<html><head><meta http-equiv=3D"Content-Type"
content=3D"text/html; =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;"
class=3D""><br =
class=3D""><div><br class=3D""><blockquote
type=3D"cite" class=3D""><div =
class=3D"">On 4 Jan 2018, at 22:16, Sandro Bonazzola <<a =
href=3D"mailto:sbonazzo@redhat.com"
class=3D"">sbonazzo(a)redhat.com</a>&gt;=
wrote:</div><br class=3D"Apple-interchange-newline"><div
class=3D""><div =
dir=3D"ltr" class=3D""><br class=3D""><div
class=3D"gmail_extra"><br =
class=3D""><div class=3D"gmail_quote">2018-01-04 17:21
GMT+01:00 Yaniv =
Kaul <span dir=3D"ltr" class=3D""><<a
href=3D"mailto:ykaul@redhat.com" =
target=3D"_blank"
class=3D"">ykaul@redhat.com</a>></span>:<br =
class=3D""><blockquote class=3D"gmail_quote"
style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr" =
class=3D""><br class=3D""><div
class=3D"gmail_extra"><br class=3D""><div =
class=3D"gmail_quote"><span class=3D"">On Thu, Jan 4, 2018 at
12:31 PM, =
Barak Korren <span dir=3D"ltr" class=3D""><<a =
href=3D"mailto:bkorren@redhat.com" target=3D"_blank" =
class=3D"">bkorren(a)redhat.com</a>&gt;</span> wrote:<br =
class=3D""><blockquote class=3D"gmail_quote"
style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span =
class=3D"m_438005550949541432gmail-">On 4 January 2018 at 09:24, Marcel =
Hanke <<a href=3D"mailto:marcel.hanke@1und1.de"
target=3D"_blank" =
class=3D"">marcel.hanke(a)1und1.de</a>&gt; wrote:<br
class=3D"">
> Hi,<br class=3D"">
> besides the kernel and microcode updates are there also updates of =
ovirt-<br class=3D"">
> engine and vdsm nessessary and if so, is there a timeline when the =
patches can<br class=3D"">
> be expected?<br =
class=3D""></span></blockquote></span></div></div></div></blockquote></div=
</div></div></div></blockquote><div><br
class=3D""></div>yes there =
are</div><div>right
after the base OS is completely =
covered</div><div><br class=3D""><blockquote
type=3D"cite" class=3D""><div=
class=3D""><div dir=3D"ltr" class=3D""><div
class=3D"gmail_extra"><div =
class=3D"gmail_quote"><blockquote class=3D"gmail_quote"
style=3D"margin:0 =
0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div
dir=3D"ltr" =
class=3D""><div class=3D"gmail_extra"><div
class=3D"gmail_quote"><span =
class=3D""><blockquote class=3D"gmail_quote"
style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span =
class=3D"m_438005550949541432gmail-">
> If there are Patches nessessary will there also be updates for =
ovirt 4.1 or<br class=3D"">
> only 4.2?<br =
class=3D""></span></blockquote></span></div></div></div></blockquote></div=
</div></div></div></blockquote><div><br
class=3D""></div>4.1 will be =
covered</div><div><br class=3D""><blockquote
type=3D"cite" class=3D""><div=
class=3D""><div dir=3D"ltr" class=3D""><div
class=3D"gmail_extra"><div =
class=3D"gmail_quote"><blockquote class=3D"gmail_quote"
style=3D"margin:0 =
0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div
dir=3D"ltr" =
class=3D""><div class=3D"gmail_extra"><div
class=3D"gmail_quote"><span =
class=3D""><blockquote class=3D"gmail_quote"
style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span =
class=3D"m_438005550949541432gmail-">
<br class=3D"">
</span>Looking at the relevant Red Hat announcement:<br class=3D"">
<a =
href=3D"https://access.redhat.com/security/vulnerabilities/speculati...
ution" rel=3D"noreferrer" target=3D"_blank" =
class=3D"">https://access.redhat.com/secu<wbr =
class=3D"">rity/vulnerabilities/speculati<wbr =
class=3D"">veexecution</a><br class=3D"">
<br class=3D"">
It seems that no packages that are derived directly from oVirt were =
updated.<br =
class=3D""></blockquote></span></div></div></div></blockquote></div></div>=
</div></div></blockquote><div><br
class=3D""></div>they are, the page is =
updating as it progresses</div><div><br
class=3D""><blockquote =
type=3D"cite" class=3D""><div class=3D""><div
dir=3D"ltr" class=3D""><div =
class=3D"gmail_extra"><div
class=3D"gmail_quote"><blockquote =
class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc =
solid;padding-left:1ex"><div dir=3D"ltr"
class=3D""><div =
class=3D"gmail_extra"><div class=3D"gmail_quote"><span =
class=3D""><blockquote class=3D"gmail_quote"
style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
You can see qemu-kvm-rhev there, which is quemu-kvm-ev in CentOS -<br =
class=3D"">
that used to be distributed by oVirt, but these days its is shipped =
as<br class=3D"">
part of the CentOS VirtSIG repo.<br class=3D"">
<br class=3D"">
AFAIK none of those components were released on CentOS yet, so if<br =
class=3D"">
you're running oVirt on CentOS you'll need to wait.<br =
class=3D""></blockquote><div class=3D""><br
class=3D""></div></span><div =
class=3D"">CentOS kernel, microcode_ctl and linux-firmware have been =
released.</div><div class=3D"">See [1] for example. I'm sure
others will =
follow.</div><div class=3D"">Y.</div><div
class=3D""><br =
class=3D""></div><div class=3D"">[1] <a =
href=3D"https://lists.centos.org/pipermail/centos-announce/2018-Janu...
2696.html" target=3D"_blank"
class=3D"">https://lists.centos.org/<wbr =
class=3D"">pipermail/centos-announce/<wbr =
class=3D"">2018-January/022696.html</a></div><span
class=3D""><div =
class=3D""> </div></span></div></div></div></blockquote><div
=
class=3D""><br class=3D""></div><div
class=3D"">qemu-kvm-ev has also =
been tagged for release, will be in next batch or earlier if I can find =
kbsing for manually push it.</div><div class=3D""><br =
class=3D""></div><div class=3D""><br
class=3D""></div><div class=3D""><br =
class=3D""></div><div
class=3D""> </div><blockquote =
class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc =
solid;padding-left:1ex"><div dir=3D"ltr"
class=3D""><div =
class=3D"gmail_extra"><div class=3D"gmail_quote"><span =
class=3D""><blockquote class=3D"gmail_quote"
style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br class=3D"">
I suppose oVirt packages and install scripts will be updated over the<br =
class=3D"">
next few days to require the newer packages, but you do not need to<br =
class=3D"">
wait for those updates to patch your systems, you can probably patch<br =
class=3D"">
as soon as the updates are made available.<br =
class=3D""></blockquote></span></div></div></div></blockquote></div></div>=
</div></div></blockquote><div><br
class=3D""></div>I suggest to start =
with the kernel</div><div>But please do read up on the various variants =
and mitigations. You may not necessarily need all of =
them</div><div>Also, you may lack the right firmware/microcode updates =
from your CPU vendor at the moment. Red Hat's microcode package only =
contains those which were released by Intel/AMD so far.</div><div><br =
class=3D""></div><div>Thanks,</div><div>michal</div><div><br
=
class=3D""><blockquote type=3D"cite"
class=3D""><div class=3D""><div =
dir=3D"ltr" class=3D""><div
class=3D"gmail_extra"><div =
class=3D"gmail_quote"><blockquote class=3D"gmail_quote"
style=3D"margin:0 =
0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div
dir=3D"ltr" =
class=3D""><div class=3D"gmail_extra"><div
class=3D"gmail_quote"><span =
class=3D""><blockquote class=3D"gmail_quote"
style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br class=3D"">
Once updates are available, a new node and engine-apppliance images<br =
class=3D"">
will probably also be built and released.<br class=3D"">
<br class=3D"">
Please note that the above as mostly a rough estimate based on my<br =
class=3D"">
familiarity with the processes involved, I am not directly affiliated<br =
class=3D"">
with any of the teams handling the response to these CVEs.<br class=3D"">
<span class=3D"m_438005550949541432gmail-HOEnZb"><font
color=3D"#888888" =
class=3D""><br class=3D"">
--<br class=3D"">
Barak Korren<br class=3D"">
RHV DevOps team , RHCE, RHCi<br class=3D"">
Red Hat EMEA<br class=3D"">
<a
href=3D"http://redhat.com/" rel=3D"noreferrer"
target=3D"_blank" =
class=3D"">redhat.com</a> | TRIED. TESTED. TRUSTED. | <a =
href=3D"http://redhat.com/trusted" rel=3D"noreferrer"
target=3D"_blank" =
class=3D"">redhat.com/trusted</a><br class=3D"">
</font></span><div
class=3D"m_438005550949541432gmail-HOEnZb"><div =
class=3D"m_438005550949541432gmail-h5">______________________________<wbr
=
class=3D"">_________________<br class=3D"">
Users mailing list<br class=3D"">
<a href=3D"mailto:Users@ovirt.org" target=3D"_blank" =
class=3D"">Users(a)ovirt.org</a><br class=3D"">
<a
href=3D"http://lists.ovirt.org/mailman/listinfo/users" =
rel=3D"noreferrer" target=3D"_blank" =
class=3D"">http://lists.ovirt.org/mailman<wbr =
class=3D"">/listinfo/users</a><br class=3D"">
</div></div></blockquote></span></div><br
class=3D""></div></div>
<br class=3D"">______________________________<wbr =
class=3D"">_________________<br class=3D"">
Users mailing list<br class=3D"">
<a href=3D"mailto:Users@ovirt.org"
class=3D"">Users(a)ovirt.org</a><br =
class=3D"">
<a
href=3D"http://lists.ovirt.org/mailman/listinfo/users" =
rel=3D"noreferrer" target=3D"_blank" =
class=3D"">http://lists.ovirt.org/<wbr =
class=3D"">mailman/listinfo/users</a><br class=3D"">
<br class=3D""></blockquote></div><br
class=3D""><br clear=3D"all" =
class=3D""><div class=3D""><br
class=3D""></div>-- <br class=3D""><div =
class=3D"gmail_signature"
data-smartmail=3D"gmail_signature"><div =
dir=3D"ltr" class=3D""><div class=3D""><div
dir=3D"ltr" class=3D""><div =
class=3D""><div dir=3D"ltr" class=3D""><div
class=3D""><div dir=3D"ltr" =
class=3D""><div class=3D""><div dir=3D"ltr"
class=3D""><div dir=3D"ltr" =
class=3D""><div dir=3D"ltr" class=3D""><div
dir=3D"ltr" class=3D""><div =
style=3D"font-family: overpass, sans-serif; font-weight: bold; margin: =
0px; padding: 0px; font-size: 14px; text-transform: uppercase;" =
class=3D""><span
class=3D"">SANDRO</span> <span =
class=3D"">BONAZZOLA</span></div><p style=3D"font-family:
overpass, =
sans-serif; font-size: 10px; margin: 0px 0px 4px; text-transform: =
uppercase;" class=3D""><span class=3D"">ASSOCIATE
MANAGER, SOFTWARE =
ENGINEERING, EMEA ENG VIRTUALIZATION R&D</span></p><div =
style=3D"font-family: overpass, sans-serif; margin: 0px; font-size: =
10px; color: rgb(153, 153, 153);" class=3D""><a =
href=3D"https://www.redhat.com/"
style=3D"color:rgb(0,136,206);margin:0px"=
target=3D"_blank" class=3D"">Red Hat <span =
class=3D"">EMEA</span></a></div><table
border=3D"0" style=3D"font-family: =
overpass, sans-serif; font-size: inherit;" class=3D""><tbody =
class=3D""><tr class=3D""><td width=3D"100px"
class=3D""><a =
href=3D"https://red.ht/sig" target=3D"_blank"
class=3D""><img =
src=3D"https://www.redhat.com/profiles/rh/themes/redhatdotcom/img/lo...
-hat-black.png" width=3D"90" height=3D"auto"
class=3D""></a></td><td =
style=3D"font-size:10px" class=3D""><div
class=3D""><a =
href=3D"https://redhat.com/trusted" =
style=3D"color:rgb(204,0,0);font-weight:bold" target=3D"_blank" =
class=3D"">TRIED. TESTED. =
TRUSTED.</a></div></td></tr></tbody></table><br =
class=3D""></div></div></div></div></div></div></div></div></div></div></d=
iv></div></div>
</div></div>
_______________________________________________<br class=3D"">Users =
mailing list<br class=3D""><a href=3D"mailto:Users@ovirt.org"
=
class=3D"">Users(a)ovirt.org</a><br =
class=3D"">http://lists.ovirt.org/mailman/listinfo/users<br =
class=3D""></div></blockquote></div><br
class=3D""></body></html>=
--Apple-Mail=_78F19FC9-4529-459D-8AFF-F81CDA40E6C7--