Major Linux distros have Meltdown patches, but that’s only part of the fix

All the major Linux distributions have now released their Intel chip meltdown patches. But, someone must retune all those servers to get their performance up to speed and replace network devices and servers running up-to-date Linux distros.

The Intel Meltdown security problem is the pain that just keeps hurting. Still, there is some good news. Ubuntu and Debian Linux have patched their distributions. The bad news? It’s becoming clearer than ever that fixing Meltdown causes significant performance problems. Worst still, many older servers and appliances are running insecure, unpatchable Linux distributions.

But first, let’s look at what happens to performance with the patches. Red Hat’s Meltdown/Spectre performance benchmarks found with the Linux Meltdown patches have the following performance problems:

  • Measurable: 8 percent to 19 percent — Highly cached random memory with buffered I/O, OLTP database workloads, and benchmarks with high kernel-to-user space transitions are impacted between 8 percent to 19 percent. Examples include OLTP Workloads (tpc), sysbench, pgbench, netperf (< 256 byte), and fio (random I/O to NvME).
  • Modest: 3 percent to 7 percent — Database analytics, Decision Support System (DSS), and Java VMs are impacted less than the “Measurable” category. These applications may have significant sequential disk or network traffic, but kernel/device drivers are able to aggregate requests to moderate level of kernel-to-user transitions. Examples include SPECjbb2005, Queries/Hour, and overall analytic timing (sec).
  • Small: 2 percent to 5 percent — HPC (High Performance Computing) CPU-intensive workloads are affected the least, with only 2 percent to 5 percent performance impact, because jobs run mostly in user space and are scheduled using cpu-pinning or numa-control. Examples include Linpack NxN on x86 and SPECcpu2006.
  • Minimal: Linux accelerator technologies that generally bypass the kernel in favor of user direct access are the least affected, with less than 2 percent overhead measured. Examples tested include DPDK (VsPERF at 64 byte) and OpenOnload (STAC-N). Userspace accesses to VDSO like get-time-of-day are not impacted. We expect similar minimal impact for other offloads.

 

But, as Richard Morrell, CTO and security lead of Falanx Group Ltd (LON:FLX), a cyber defense company, points out: “Many (a lot) of these devices are still running platforms that started out in the development lab at the vendor as CentOS 4/5/6/7 development trees. For the later versions that’s fine and dandy, kernel and microcode patches are available due to CentOS benefitting from the hard work Red Hat did to get the patches out for a multitude of architectures.” But, many of the older “devices are running versions 4 and 5 and have long since departed from being ‘standard builds.”

Click to view all articles for the EPIC:
Or click to view the full company profile:
Facebook
Twitter
LinkedIn
Falanx Cyber Security

More articles like this

Falanx Cyber Security plc

How to develop a data infraction response plan

A dating breach response plan outlines how an economy be respond to a breach. Follow these five steps, both use our free template to develop your organization’s plan. Data breaches happen at all organizations. Even the

Falanx Cyber Security

Thwarting the most advanced cyber threats

Cyber security is no longer what it used to be. That’s because cyber threats have become more persistent, sophisticated and voluminous, and the switch to hybrid working has only accelerated this trend. Rob Shapland from Falanx

Falanx Cyber Security

Inspecs has eyes-on Security 24/7/365

Background Inspecs Group Plc is global leader producing large volumes of high quality eyewear for fashion, sports, lifestyle brands and patented concept eyewear. The Inspecs group of companies produce in-house for a global network of distribution to

Falanx Cyber Security

Don’t let hackers ruin your holidays

Holidays are approaching and now is the time of year when IT staff and business owners start to wind down. But this is the busy season for ‘holiday hackers’. The week prior to and during Christmas

Falanx Cyber Security

Falanx Group further progress in sales with good order growth

Falanx Group Ltd (LON:FLX), the AIM listed provider of cyber security services, has announced its interim results for the six months ended 30 September 2022. Financial Highlights for six months to 30 September 2022 • Orders for our core

Falanx Cyber Security

Hospitals are at a high risk of cyberattacks

Are Hospitals at a High Risk of cyberattacks? Yes, they are! Since they store sensitive data and usually have weak cyber defences. Thus, putting Digital Health at stake. Even the pandemic has raised the increase in the rate of cyberattacks on Hospitals

Falanx Cyber Security

How to avoid the $1 million bill of a ransomware attack

Your business will be targeted by a cybercriminal this year. That’s not an exaggeration, or even a scare tactic. Unfortunately, it is the harsh reality: 61% of mid-sized businesses (the most popular target for hackers) experienced a cyberattack last

Falanx Cyber Security

Finalists at the Cyber Security Awards 2022

Falanx Group are delighted to have 2 finalists at the Cyber Security Awards, 2022 being held at One Moorgate Place, London! Nicola Hartland, Chief Revenue Officer, is finalist in the category Woman of the Year. Rob Shapland,

Falanx Cyber Security

Charities Cyber Essentials fortnight 7-18th November

Cyber criminals are attracted to money. And that makes charities – and the information they hold – a target. Data on beneficiaries, supporters and volunteers as well as information on invoice and payment details can be

Falanx Cyber Security

Most Inspiring Women in Cyber awards 2022

The nominations for the Most Inspiring Women in Cyber awards are out! It’s always wonderful to read about the incredible women in our industry, who are making fantastic contributions and paving the way for others. In

Falanx Cyber Security

Almost half of Irish SMEs hit by multiple cyber attacks

Almost half of Irish small and medium businesses have experienced multiple cyber attacks in the last three years, according to a new study. The study from Microsoft and Vodafone states that the average financial loss per

Falanx Cyber Security

Falanx Group strengthens Board with new appointments

Falanx Group Ltd (LON:FLX), the AIM listed provider of cyber security services, has announced the appointment of William Kilmer as an independent Non-Executive Director and Richard “Rick” Flood as an Executive Director and with immediate effect.