Muva nje, ngikuthole emahoreni ambalwa adlule, kutholakele ukuba sengozini okuningi okuthinta amaprosesa we-Intel kusuka ngo-2011 kuze kube namuhla. Lokhu kwehluleka kwaziwa njengeMicroarchitectural Data Sampling (MDS) kanye ICanonical isivele ikhiphe izinhlobo ezintsha ze-kernel ye-Ubuntu kanye nakho konke okunye ukunambitheka kwayo okusemthethweni, esikukhumbulayo yiKubuntu, Lubuntu, Xubuntu, Ubuntu Budgie, Ubuntu Mate, Ubuntu Studio ne-Ubuntu Kylin. Izinhlobo ezintsha zifika ngezinombolo ezingu-5.0.0.15.16, inqobo nje uma siseDisco Dingo.
Njengoba sifunda ku inothi elifundisayo, ingqikithi ye- amaphutha amane okuphepha lapho i-Intel isivele ikhiphe i-firmware microcode yayo ukubhekana nale nkinga, kepha lawa ma-firmwares awakwazanga ukusetshenziswa ezinhlelweni ezisebenzayo ze-Linux, ngakho-ke yizinkampani ezithuthukisa amasistimu okumele zikhulule izinhlobo ezintsha ze-kernel ne-QEMU yazo. Kuyafaneleka ukukhumbula ukuthi lesi yisikhathi esihle sokuzama inketho ye-Live Patch eza neDisco Dingo, esivumela ukuthi sifake izinhlobo ezintsha zeKernel ngaphandle kokuqalisa kabusha uhlelo.
Ukulungiswa kwe-Canonical amaphutha we-4 MDS security
Zonke izimbungulu ezine zithinta ama-processor amaningi we-Intel futhi zingavumela (uma singathuthukisi) a umsebenzisi ononya odalula imininingwane ebucayi. Inkinga ithinta zonke izinhlobo ze-X-Buntu, phakathi kwazo okusasekelwa kuzo i-19.04, 18.10, 18.04, 16.04 ne-14.04, eyokugcina enguqulweni ye-ESM. Futhi kuyisikhathi esihle sokuqinisekisa ukuthi ukwesekwa kwe-ESM okungezwe eminyakeni yekhalenda emihlanu kuyasebenza.
Njengokujwayelekile lapho kukhishwa izibuyekezo zokuphepha, Canonical us incoma ukubuyekeza ngokushesha okukhulu. Ngakolunye uhlangothi, iphinda income ukukhubaza i-SMT (Symmetric Multi-Threading noma i-Hyper-Threading) evela ku-BIOS, into ezohluka ngokuya ngekhompyutha kanye nohlobo lwayo lwe-BIOS.
Yize sike sasho phambilini ukuthi i-Live Patch isivimbela ukuthi siqale kabusha lapho sifaka izinhlobo ezintsha ze-Kernel, kulokhu kungasisiza ukuthi siqinisekise ukuthi awukho umyalezo ovelayo osicela ukuthi siqale phansi, kepha iCanonical uncoma ukuqala kabusha ikhompyutha ngenxa yobukhulu bamaphutha ezokuphepha atholakele. Uhlobo olusha lwe-intel-microcode ngu 3.20190514.0. Okuhlukile yinguqulo ye-kernel, futhi inguqulo ye-Disco Dingo eshiwo ngaphambili ingeziwe 4.18.0.20.21 ye-Ubuntu 18.10, 4.15.0-50.54 ye-Ubuntu 18.04 LTS ne- 4.4.0-148.174 ye-Ubuntu 16.04 LTS ne-14.04 ESM. Uyazi: buyekeza manje, ngalokho okungenzeka.