Xen Security Update

This update addresses the Meltdown vulnerability for CentOS 6/7 Xen static compute resources. For more information, refer to Meltdown and Spectre CPU Issues.

The new kernel implements Kernel Page Table Isolation (KPTI) to mitigate the Meltdown vulnerability. The kernel should be updated to one of the following versions:

  • for CentOS 6 - kernel-4.9.75-30.el6.x86_64
  • for CentOS 7 - kernel-4.9.75-29.el7.x86_64

To install the update:

  1. Run the following command:

    1
    
    /onapp/onapp-hv-install/onapp-hv-xen-install.sh
    
  2. Reboot the compute resource for the new kernel to take effect.