sb-as logo
Story image

Stop patching Spectre & Meltdown issues or risk reboot problems, Intel warns

25 Jan 2018

Intel is warning all users to stop downloading patches for the Spectre and Meltdown vulnerabilities because they are causing system reboot issues for a number of machines.

On January 11 Intel received reports from customers that they were experiencing higher system reboots after installing the patches.

“Specifically, these systems are running Intel Broadwell and Haswell CPUs for both client and data center. We are working quickly with these customers to understand, diagnose and address this reboot issue. If this requires a revised firmware update from Intel, we will distribute that update through the normal channels.  We are also working directly with data center customers to discuss the issue,” the company said at the time.

This week Intel discovered the root cause of the issue and says it has made good progress towards a solution. The company will distribute the new solution to partners for testing this weekend and will release a final solution available once testing has finished.

In the meantime, Intel says customers and partners should stop installing current releases.

“We recommend that OEMs, cloud service providers, system manufacturers, software vendors and end users stop deployment of current versions, as they may introduce higher than expected reboots and other unpredictable system behaviour,” the company says.

This applies to all users affected by the Meltdown and Spectre vulnerabilities, which includes a number of Intel Core, Intel Xeon, Intel Atom, Intel Celeron and Intel Pentium processors. See the full list here. “We ask that our industry partners focus efforts on testing early versions of the updated solution so we can accelerate its release. We expect to share more details on timing later this week.”

Intel also says customers must be vigilant in their efforts to keep systems up to date and to maintain security best practice.

Earlier this month Intel CEO Brian Krzanich wrote an open letter to tech leaders that reinforced Intel’s commitment to customers and to fixing the issues.

He explained that the company approaches the updates with ‘customer-first’ urgency, timely and transparent communications and the ongoing pledge to customer security.

“To accelerate the security of the entire industry, we commit to publicly identify significant security vulnerabilities following rules of responsible disclosure and, further, we commit to working with the industry to share hardware innovations that will accelerate industry-level progress in dealing with side-channel attacks. We also commit to adding incremental funding for academic and independent research into potential security threats,” he wrote.

“The bottom line is that continued collaboration will create the fastest and most effective approaches to restoring customer confidence in the security of their data. This is what we all want and are striving to achieve.”

Story image
Cisco report: Remote working is here to stay, making cybersecurity a top priority
"With this new way of working here to stay and organisations looking to increase their investment in cybersecurity, there’s a unique opportunity to transform the way we approach security as an industry to better meet the needs of our customers and end-users.”More
Story image
COVID-related email subjects biggest threat in phishing scams
Coronavirus-related email subjects remain the biggest threat in phishing scams, a new study has found.More
Story image
Revealed: Imperva publishes research on decade old botnet, responsible for millions of attacks
Imperva Research Labs has revealed findings of a six-month intensive investigation into a botnet that has been exploiting CMS vulnerabilities.More
Story image
Video: 10 Minute IT Jams - protecting data with user behaviour analytics
In this video, Forcepoint senior sales engineer and solutions architect Matthew Bant discusses the company's DLP solution, the importance of integrating compliance into security solutions, and why cybersecurity strategies should take a more people-based approach.More
Story image
Secureworks: Remote working exposes new security vulnerabilities
New vulnerabilities have been exposed as IT teams across the world respond to the ongoing COVID-19 pandemic.More
Story image
New project development inhibited by cybersecurity, Kaspersky research states
"There are still some practical steps that can be taken to make sure that an emerging technology or a product reaches its launch. Cybersecurity doesn’t have to be another corporate barrier, but it should be on an integral part of the project all long."More