Skip to main content
Contributor III
April 10, 2020

Technical Note: CSTN 00001 - Meltdown/Spectre vulnerability Patch Rollout Update Instructions

  • April 10, 2020
  • 0 replies
  • 1011 views
Description

This document provides the details for applying the Meltdown/Spectre vulnerability patch to your instance of CyOPsâ„¢. The updated and new kernel of Linux CentOS version 3.10.0-693.17, as well as CyOPsâ„¢ 4.10.3 and later, will already contain the patch.


Important: Ensure that you take a snapshot of the VM in both ESXI and AWS before making any changes or applying any patches. DO NOT SKIP THIS STEP.


Notes in case of CyOPsâ„¢ 4.10.3

  • If you are performing a fresh installation of CyOPsâ„¢, i.e., importing the CyOPsâ„¢ 4.10.3 OVA, then the OVA already contains the Meltdown/Spectre vulnerability patch and you do not require to perform any of additional steps.
  • If you are upgrading your CyOPsâ„¢ instance to 4.10.3 from an older version of CyOPsâ„¢, then you must perform the following additional commands apply the Meltdown/Spectre vulnerability patch to your CyOPsâ„¢ instance.

Solution

Run the following commands from the command prompt of your CyOPsâ„¢ instance. Note that you need to use sudo if you are trying to run the commands as the csadmin user:

  1. wget https://update.cybersponse.com/other/update-cyops-os.sh
  2. chmod +x update-cyops-os.sh
  3. ./update-cyops-os.sh
  4. reboot


The 'update-cyops-os.sh' script performs the following tasks:

  1. Creates a new repository file: /etc/yum.repos.d/cs-libselinux.repo.
  2. Disables the cs-app and cs-connectors repositories.
  3. Moves the /boot/*3.10.0-514* files to /temp_kernel_files.
  4. Stops the required services using the /opt/cyops/configs/scripts/services.sh script.
  5. Installs the OS and kernel updates.
  6. Re-enables the cs-app and cs-connectors repositories.
  7. Requests the user to reboot the instance.


Once your CyOPsâ„¢ instance is rebooted, run the 'uname -r' command to ensure that your system is using the newly upgraded kernel. The command should display the kernel version as 3.10.0-693.17.


The following messages are seen on AWS instances post upgrade. You can ignore these errors during the cleanup stage. These messages come from the uninstallation of the previous kernel:


usr/lib/dracut/modules.d/40network/module-setup.sh: line 31: /lib/modules/3.10.0-514.21.2.el7.x86_64///lib/modules/3.10.0-514.21.2.el7.x86_64/kernel/drivers/net/wan/hdlc.ko: No such file or directory
/usr/lib/dracut/modules.d/40network/module-setup.sh: line 31: /lib/modules/3.10.0-514.21.2.el7.x86_64///lib/modules/3.10.0-514.21.2.el7.x86_64/kernel/drivers/net/wan/hdlc_raw.ko: No such file or directory
/usr/lib/dracut/modules.d/50drm/module-setup.sh: line 26: /lib/modules/3.10.0-514.21.2.el7.x86_64///lib/modules/3.10.0-514.21.2.el7.x86_64/kernel/drivers/gpu/drm/nouveau/nouveau.ko: No such file or directory
/usr/lib/dracut/modules.d/50drm/module-setup.sh: line 26: /lib/modules/3.10.0-514.21.2.el7.x86_64///lib/modules/3.10.0-514.21.2.el7.x86_64/kernel/drivers/gpu/drm/udl/udl.ko: No such file or directory
/usr/lib/dracut/modules.d/90kernel-modules/module-setup.sh: line 14: /lib/modules/3.10.0-514.21.2.el7.x86_64///lib/modules/3.10.0-514.21.2.el7.x86_64/kernel/drivers/gpio/gpio-ich.ko: No such file or directory
/usr/lib/dracut/modules.d/90kernel-modules/module-setup.sh: line 14: /lib/modules/3.10.0-514.21.2.el7.x86_64///lib/modules/3.10.0-514.21.2.el7.x86_64/kernel/drivers/gpio/gpio-viperboard.ko: No such file or directory


Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!