This post is more than 5 years old

15 Posts

2438

February 1st, 2018 12:00

Isilon and spectre/meltdown vulnerbilities

Hi,

As per article 516617 (link below) and the recent spectre/meltdown vulnerabilities, the article states the Isilon

is affected and   combination of OneFS and BIOS updates will be provided.


Does anyone knows if any updates available for OneFS and BIOS  or when it will be available to apply.


http://support.emc.com/kb/516117


FYI


Isilon A100 Backup Accelerator
A100 Performance Accelerator
A200
A2000
F800
H400
H500
H600
HD400
IQ Accelerator-x
IQ Backup Accelerator-x
NL400
NL410
S200
S210
X200
X210
X400
X410
OneFS 8.1.x,
OneFS 8.0.x, OneFS 7.2.1.x, OneFS 7.2.0.x, OneFS 7.1.1.x, OneFS 7.1.0.x
Yes A combination of OneFS and BIOS updates will be provided.

Thank you !

252 Posts

February 5th, 2018 08:00

Hi Nirvik,

I don't have an exact date for you, but the support team with Isilon has been instructing people that the article you provided will be updated with more information as it is available. At this time, your best bet is to continue checking the article for further updates.


http://support.emc.com/kb/516117

33 Posts

February 6th, 2018 10:00

The key with meltdown is ability to execute local code on the hardware.  If you only allow ssh access to trusted parties the only risk would be a remote exploit. I have no firsthand knowledge of EMC or OneFS development but given the fact that it borrows heavily from FreeBSD and, last I checked, they are still working on a patch I would expect a full mitigation to be a ways out.  Unfortunately FreeBSD was left out of the embargo so they are still playing catch-up and it's likely that backports and/or testing will take some time.

Top