We need to patch and reboot all labvirts and VMs, as soon as proper packages are available.
Response coordination checklist: https://etherpad.wikimedia.org/p/cloud-meltdown-rollout
Canary notice:
https://lists.wikimedia.org/pipermail/cloud/2018-January/000167.html
Full reboots notice:
https://lists.wikimedia.org/pipermail/cloud/2018-January/000175.html
Patch tracking:
- Debian: https://security-tracker.debian.org/tracker/CVE-2017-5754
- Ubuntu: https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-5754.html
- Ubuntu initial bug in fix: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1741934/comments/17
Docs:
https://wikitech.wikimedia.org/wiki/Portal:Cloud_VPS/Admin/Maintenance#Labvirt_reboot_checklist
Related
Prod {T184256}
PCID https://groups.google.com/forum/m/#!topic/mechanical-sympathy/L9mHTbeQLNU
PCID & INVPCID https://lwn.net/Articles/671299/
https://bugs.chromium.org/p/project-zero/issues/detail?id=1272#c3