• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Security Vulnerability In VIOS, AIX, And Maybe IBM i

    November 23, 2020 Timothy Prickett Morgan

    IBM i shops that use the Virtual I/O Server, which is a cut-down version of the AIX implementation of Unix created by Big Blue, have to be aware that there is a security vulnerability that affects recent releases of AIX and VIOS.

    The vulnerability, announced in Security Vulnerability CVE-2020-4788, affects Power9 machinery running VIOS 3.1 or AIX 7.1 and AIX 7.2, and under what are called “extenuating circumstances” the vulnerability could allow a local user on the system to obtain sensitive information stored on the L1 cache on the Power9 cores.

    The vulnerability was reported on November 18, and the Openwall security site published a more detailed, English language description of the issue at this link. The vulnerability appears to be in the same class as other speculative execution vulnerabilities that are part of most modern processors and labelled under the Spectre and Meltdown vulnerabilities that came to light out of Google a few years back. Here is the description from Openwall:

    “IBM Power9 processors can speculatively operate on data in the L1 cache before it has been completely validated, via a way-prediction mechanism. It is not possible for an attacker to determine the contents of impermissible memory using this method, since these systems implement a combination of hardware and software security measures to prevent scenarios where protected data could be leaked. However, these measures don’t address the scenario where an attacker induces the operating system to speculatively execute instructions using data that the attacker controls. This can be used for example to speculatively bypass “kernel user access prevention” techniques, as discovered by Anthony Steinhauser of Google’s Safeside Project. This is not an attack by itself, but there is a possibility it could be used in conjunction with side-channels or other weaknesses in the privileged code to construct an attack. This issue can be mitigated by flushing the L1 cache between privilege boundaries of concern.”

    IBM’s own page describing the fixes for AIX and VIOS is at this link. The patches were turned around fast and were available on November 20. The Linux community has also been notified and pushed some fixes upstream to the Linux kernel developers in the open source community. IBM is also researching what impact, if any, might affect IBM i itself and we will be keeping an eye on that. Check the IBM i PTF Guide in the coming days for more on that.

    As far as we know, no one has created a malware exploit that takes advantage of this vulnerability on any of the IBM platforms mentioned above.

    RELATED STORIES

    The Herculean Task Of Applying Spectre/Meltdown Patches

    Power Systems And The Spectre And Meltdown Threats

    Update On The Spectre And Meltdown Patches For Power

    The Performance Impact Of Spectre And Meltdown

    IBM i Gets More PTFs for Meltdown and Spectre

    IBM i PTF Guide, Volume 20, Number 4, The Spectre Of Meltdowns

    IBM i PTF Guide, Volume 20, Number 3: Important Update For Spectre/Meltdown

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: AIX, IBM i, IBM i PTF Guide, Linux, Malware, Meltdown, Openwall, Power9, Spectre, Spectre/Meltdown, Unix, VIOS, Virtual I/O Server

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    IBM i PTF Guide, Volume 22, Number 47 IBM Reveals Power10 Rollout Plan, Begins Power11

    Leave a Reply Cancel reply

TFH Volume: 30 Issue: 75

This Issue Sponsored By

  • Blair Technology Solutions
  • IBM
  • Computer Keyes
  • Profound Logic Software
  • UCG Technologies

Table of Contents

  • Frank Soltis Discusses A Possible Future for Single-Level Storage
  • Why POWER8 Is Sometimes The Best Platform To Run SAP HANA
  • IBM Reveals Power10 Rollout Plan, Begins Power11
  • Security Vulnerability In VIOS, AIX, And Maybe IBM i
  • IBM i PTF Guide, Volume 22, Number 47

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • The Power11 Transistor Count Discrepancies Explained – Sort Of
  • Is Your IBM i HA/DR Actually Tested – Or Just Installed?
  • Big Blue Delivers IBM i Customer Requests In ACS Update
  • New DbToo SDK Hooks RPG And Db2 For i To External Services
  • IBM i PTF Guide, Volume 27, Number 33
  • Tool Aims To Streamline Git Integration For Old School IBM i Devs
  • IBM To Add Full System Replication And FlashCopy To PowerHA
  • Guru: Decoding Base64 ASCII
  • The Price Tweaking Continues For Power Systems
  • IBM i PTF Guide, Volume 27, Numbers 31 And 32

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle