HPE, Dell EMC Warn Customers Over Spectre, Meltdown Patches

Hewlett Packard Enterprise and Dell EMC, two of the biggest suppliers of enterprise data center gear, have issued new warnings about the Spectre and Meltdown patches from Intel.

Scott Ferguson, Managing Editor, Light Reading

January 25, 2018

3 Min Read

Following fresh warnings from Intel to users earlier this week, Hewlett Packard Enterprise and Dell EMC have each issued warnings to their customers about patches related to the Spectre and Meltdown CPU vulnerabilities.

[company link 13970 not found] and [company link 14177 not found] are two of the largest suppliers of data center and cloud computing equipment to enterprises, meaning that any warnings from them about the Spectre and Meltdown patches could have far-ranging consequences for IT departments, as well as security pros. (See Unknown Document 740007.)

The security bulletins from HPE and Dell EMC follow a statement from Intel Corp. (Nasdaq: INTC) on January 22 that warned about unexpected system reboots, as well as other problems specifically related to the Spectre patch. This warning from the chipmaker was directed at nearly everyone and everything in the tech industry, including OEMs, cloud service providers, system manufacturers, software vendors and end users.

(Source: Jarmoluk via Pixabay)

(Source: Jarmoluk via Pixabay)

The latest warnings from Intel were met by large complaints from many in the tech community, including Linux founder Linus Torvalds, who offered less-than-cordial assessment of what the chipmaker has been doing to address the issue. (See Linus Torvalds: Intel's Spectre Patch Is 'Complete & Utter Garbage'.)

In its message to customers, HPE notes that the company has not put the patch into production and that any servers that ship from its factories have the proper BIOS version to avoid problems.

However, customers should be aware about downloading the patch from the company website.

"The alert does apply to customers that recently downloaded the System ROM update with the Intel microcode patch from the HPE website," according to HPE.

Dell EMC pushed out a similar warning to its customers, noting: "Dell is advising that all customers should not deploy the BIOS update for the Spectre (Variant 2) vulnerability at this time. We have removed the impacted BIOS updates from our support pages and are working with Intel on a new BIOS update that will include new microcode from Intel."

The fundamentals of network security are being redefined -- don't get left in the dark by a DDoS attack! Join us in Austin from May 14-16 at the fifth-annual Big Communications Event. There's still time to register and communications service providers get in free!

As the Dell EMC warning indicates, there are several different variants associated with these chip vulnerabilities. Variants 1 and 2 relate to Spectre, while Variant 3 is for Meltdown. Of the three, Variant 2 has given Intel and its partners the most difficulty with a wide variety of the company's CPUs.

Specifically, Variant 2 involves a flaw called "indirect branch speculation," which is difficult to patch, and can make certain types of environments susceptible to attacks. Intel offered a fix called Indirect Branch Restricted Speculation or IBRS, which is the part of the patching that restricts speculation of indirect program branches.

It was this patch that caused Torvalds to lash out: "So the IBRS garbage implies that Intel is _not_ planning on doing the right thing for the indirect branch speculation."

In its own report on the Variant 2 flaw, Google (Nasdaq: GOOG) noted in a blog post that it had come up with a approach called Retpoline -- a binary modification technique that prevents branch-target-injection. This allowed key performance issues to continue and ensured that an attacker could not take advantage of the flaw by manipulating the execution commands. (See Unknown Document 740007.)

Related posts:

— Scott Ferguson, Editor, Enterprise Cloud News. Follow him on Twitter @sferguson_LR.

Read more about:

Security Now

About the Author(s)

Scott Ferguson

Managing Editor, Light Reading

Prior to joining Enterprise Cloud News, he was director of audience development for InformationWeek, where he oversaw the publications' newsletters, editorial content, email and content marketing initiatives. Before that, he served as editor-in-chief of eWEEK, overseeing both the website and the print edition of the magazine. For more than a decade, Scott has covered the IT enterprise industry with a focus on cloud computing, datacenter technologies, virtualization, IoT and microprocessors, as well as PCs and mobile. Before covering tech, he was a staff writer at the Asbury Park Press and the Herald News, both located in New Jersey. Scott has degrees in journalism and history from William Paterson University, and is based in Greater New York.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like

More Insights