Late Breaking Documentation Updates for Oracle ILOM 3.2.x Firmware
The following table lists the latest documentation updates available for Oracle ILOM
3.2.x firmware.
Note -
The information provided in the document was not previously published in the
Oracle ILOM 3.2 documentation set.
|
|
|
|
|
3.2.6.7
|
Hardware BTI Mitigation
|
Oracle SPARC T4 servers
|
Setting for hardware-based mitigation for CVE-2017-5715 (Branch
Target Injection, Spectre Variant 2)
|
|
|
Configure Hardware BTI Mitigation Property on SPARC T4 Server
Refer to following information to configure the Hardware BTI Mitigation property
on an Oracle SPARC T4 Server.
User Interface Configurable Target and User
Role:
-
SP
CLI:/HOST/hw_bti_mitigation
-
Web: Host Management > Host Control
Note -
To apply property modifications made on the web Host Control page, you
must click Save
-
User Role: Reset and Host Control (r)
role is required to modify host configurable properties
|
|
|
Hardware BTI Mitigation
|
Enabled
|
Default | Enabled | Disabled
Note -
The Hardware BTI Mitigation property is available for
configuration as of Oracle ILOM firmware version 3.2.6.7 on
SPARC T4 servers.
Web interface:
-
Default – When Default is selected, the system
will use the Oracle default setting for hardware-based
mitigation for CVE-2017-5715 (Branch Target Injection,
Spectre Variant 2). The Default property is enabled by
default.
-
Enabled – Select Enabled to turn on the
hardware-based mitigation mode for CVE-2017-5715 (Branch
Target Injection, Spectre Variant 2), regardless of the
Default property value. When enabled, this property
provides a secure configuration option, but some
applications might experience lower performance.
-
Disabled – Select Disabled to turn off the
hardware-based mitigation mode for CVE-2017-5715 (Branch
Target Injection, Spectre Variant 2), regardless of the
Default property value. When disabled, the system might
be vulnerable to Branch Target Injection style attacks,
but some applications might experience improved
performance.
CLI Syntax for Hardware BTI Mitigation
for SPARC T4 Server:
set /HOST hw_bti_mitigation=
default | disabled | enabled
|
|