Last Modified:
Nothing groundbreaking here, I am just collating advisories and press releases from vendors as I find them that relate to the recently disclosed issues regarding speculative execution side-channel vulnerabilities. This is also being referred to as Spectre (variants 1 & 2) and Meltdown (variant 3). If you have any additions/corrections, please let me know in the comments, and I’ll update this post.
Disclaimer: This is my personal blog & post. This post is not an official statement or communication from Microsoft. For Microsoft’s official guidance, please see the links in the “Microsoft” section below.
Research
Microsoft
Advisories & Communications
CPU Makers
Hardware OEMs
Client OEMs
Server OEMs
Other OEMs
| Vendor | Info | Article |
| F5 | Security Advisory | https://support.f5.com/csp/article/K91229003 |
| Fortinet | Security Advisory | https://fortiguard.com/psirt/FG-IR-18-002 |
| Juniper | Security Advisory | https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10842&actp=METADATA |
| NetApp | Security Advisory | https://security.netapp.com/advisory/ntap-20180104-0001/ |
| Raspberry Pi | Blog | https://www.raspberrypi.org/blog/why-raspberry-pi-isnt-vulnerable-to-spectre-or-meltdown/ |
Cloud Providers
Virtualization
Operating Systems
Browsers
| Vendor | Info | Article |
| Google Chrome | Security Info | https://www.chromium.org/Home/chromium-security/ssca |
| Mozilla Firefox | Blog | https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ |
| Apple Safari | Security Info | https://support.apple.com/en-us/HT208403 |
| WebKit | Rendering Engine Info | https://webkit.org/blog/8048/what-spectre-and-meltdown-mean-for-webkit/ |
Mobile Devices
Databases
| Vendor | Article |
| Postgresql | https://www.postgresql.org/message-id/[email protected] |
| Oracle | Pending |
| MySQL | Pending |
Antivirus
(Hat tip to Kevin Beaumont: https://twitter.com/GossiTheDog/status/948889660780175360 (Direct GDocs Link: https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?usp=sharing&sle=true))
SaaS
Other
CERTS
Benchmarks & Performance Impacts
Benchmark Tests
Vendor Performance Assessments
| Vendor | Info | Article |
| RedHat | Performance Impacts – Describing the performance impacts to security patches | https://access.redhat.com/articles/3307751 |
| Protecting our Google Cloud customers from new vulnerabilities without impacting performance | https://www.blog.google/topics/google-cloud/protecting-our-google-cloud-customers-new-vulnerabilities-without-impacting-performance/ |