Spectre & Meltdown exploit
a few days/weeks ago, 2 exploits have been published on hardware intel, AMD, ARM, etc.
A list of processors affected has been published by ARM (https://developer.arm.com/support/security-update), it includes Cortex A9 which is used the one used by the 4 recommended devices for Replicant:
- I9100 (Galaxy S2)
- I9300 (Galaxy S3)
- N7100 (Galaxy Note 2)
- I9250 (Galaxy Nexus)
Android propose some patches this month (https://source.android.com/security/bulletin/2018-01-01).Here are several links on this topic:
- https://lists.vmware.com/pipermail/security-announce/2018/000397.html (patch VMware)
Happy new year! ;)
RE: Spectre & Meltdown exploit - Added by Kurtis Hanna about 2 months ago
This is being worked on here: https://redmine.replicant.us/issues/1886
We now are building nightly releases as of a few days ago for testing purposes: https://jenkins.minhas.io/ https://jenkins.minhas.io/nightly_builds/replicant/6.0-dev/
These nightly builds should have the spectre & Meltdown security patches included in them, but please keep in mind that these are not official stable releases, so use them at your own risk.
We're also gearing up for a Replicant 6.0 0004 and Replicant 6.0 0005 release in the near future that includes all the upstream security patches and other bug fixes and additional features. https://redmine.replicant.us/versions/41 https://redmine.replicant.us/versions/42
After these releases, our plan is to get a new Replicant release out everytime there is a security patch upstream.