Patch for Retbleed Problem Slows Down Virtual Machines on Linux by 70%

VMware engineers have tested a Linux kernel patch that addresses the Retbleed side-channel problem. The researchers came to the disappointing conclusion that this fix can affect performance, reducing it immediately by 70%.

让我提醒你,我们还讨论过 Linus Torvalds Uses Linux on an Apple MacBook Air with an M2 Processor, 还有那个 P2P Botnet Panchan Attacks Linux Servers.

Retbleed was discovered and described by experts from the ETH Zurich last summer. At the time, the bug was reported to affect 英特尔 processors from 3 到 6 years old, as well as AMD processors from 1 到 11 years old. Experts immediately warned that fixing the bug could have a negative impact on performance.

Let me remind you that Retbleed consists of two vulnerabilities (CVE-2022-29900 for AMD and CVE-2022-29901 for Intel) and belongs to the Specter-BTI class of speculative attacks (variant 2). The name Retbleed refers to the Retpoline security solution, which was developed by 谷歌 在 2018 to combat the Meltdown and Specter processor vulnerabilities. It was in the work of the Retpoline protection that fresh problems were found.

As VMware engineers now report in the Linux Kernel mailing list, the Retbleed patches do cause a noticeable performance regression in the Linux 5.19 kernel. The company’s internal tests have shown that running Linux virtual machines with the ESXi hypervisor and Linux kernel version 5.19 results in a performance drop of up to 70% with a single vCPU, A 30% drop in network performance, and up to 13% in storage performance.

If VMware testers disabled patches for Retbleed in the 5.19 kernel, ESXi performance returned to normal levels, as in version 5.18. The tests were conducted on Intel Skylake processors released between 2015 和 2017.

Since speculative computing was generally designed to speed up data processing, it is not surprising that disabling it has a very negative impact on performance. 然而, A 70% performance drop is simply unacceptable for many business processes and is a big problem.

实际上, if the patches are not improved and revised, users are faced with a clear choice: 使用 5.19 kernel and still lose performance, or stay on the previous version and take the possible risks, relying on the fact that the Retbleed problem is not so easy to exploit.

We believe that these findings will be useful to the Linux community, and wanted to document them.VMware representatives politely summarize.

关于作者

卡琳娜·威尔逊

随着超过 10 多年在线和印刷媒体写作经验, 我是提供清晰且引人注目的文案的专家.

我曾为一家领先的 SEO 文案机构撰写文章,也为一些英国最知名的品牌撰写文章, 杂志和报纸.

发表评论