3 ms·
You need both. According to https://access.redhat.com/articles/3311301 https://access.redhat.com/articles/3311301: > CVE-2017-5715 (variant #2/Spectre) is an
by ajdlinux 9y ago
You need both.
According to https://access.redhat.com/articles/3311301 https://access.redhat.com/articles/3311301:
> CVE-2017-5715 (variant #2/Spectre) is an indirect branching poisoning attack that can lead to data leakage. This attack allows for a virtualized guest to read memory from the host system. This issue is corrected with microcode, along with kernel and virtualization updates to both guest and host virtualization software. This vulnerability requires both updated microcode and kernel patches. Variant #2 behavior is controlled by the ibrs and ibpb tunables (noibrs/ibrs_enabled and noibpb/ibpb_enabled), which work in conjunction with the microcode.