跳到主要内容
博客壳牌公司Xen 安全建议和我们如何处理它们

Xen 安全提示和我们的处理方式

Xen 安全团队最近公开了三个关于Xen Hypervisor的安全建议。由于Linode在过去几周内进行了主动维护,因此Linode客户不受建议中所述问题的影响。

  • XSA-7-64位PV客户权限升级漏洞
  • XSA-8- 客人对syscall/sysenter异常生成的拒绝服务
  • XSA-9- PV客户主机拒绝服务(AMD勘误表#121)

Xen 博客对这个问题有一个非常好的写法

必须处理像这样的建议,只是我们行业的一部分。我们在几乎所有事情上的挑战之一是我们的规模。突然间,一个必要的更新意味着要处理成千上万的机器,给我们的客户造成巨大的干扰。

这些具体的建议有可能影响到我们的整个舰队,然而我们能够设计一个聪明的计划,把受影响的Linodes的数量减少到少数。该计划结合了:1)急于在所有设施中部署额外的容量储备 2)只对能恢复最多的主机进行重启/升级,以及 3)只对剩余的受影响的 Linodes 进行自动迁移排队,以获得良好的容量。因此,大多数客户没有受到这次维护的影响。

整个公司几乎每个人都参与了这项工作--为整个团队使这项工作尽可能地无缝和简化而点赞。

-克里斯

评论 (11)

  1. Author Photo

    Awesome work, Linode!

  2. Author Photo

    This is exactly why I’m with Linode. You guys take care of things seamlessly and I don’t have to worry about my server 🙂

    Keep up the excellent work Linode!

  3. Author Photo

    A pat on the back for the team!

  4. Author Photo

    Nice – I never even noticed.

  5. Author Photo

    Thank you Linode, you handled this very nicely.

  6. Author Photo

    It had a very modest impact on us, but we did wonder why only a small percentage of our linodes were affected by what we deduced was a security patch. Thanks for the explanation.

  7. Author Photo

    Well done Linode, awesome!

  8. Author Photo

    Well done, and happy almost-birthday Linode!

  9. Author Photo

    Nice, I think you handled this well, however, my systems administrator does not.

  10. Author Photo

    Awesome work, couldn’t love you guys more

  11. Author Photo

    Undiluted, pure awesomeness.
    Consistent excellence!
    I read about the vulnerability on Slashdot, clicked over to Linode and “yup it’s already fixed”. There is a huge amount of dedication and effort over time that enables you to say that.
    I thank my lucky stars the day I joined Linode.

留下回复

您的电子邮件地址将不会被公布。 必须填写的字段被标记为*