AWS Statement: Processor Speculative Execution Research Disclosure
aws.amazon.com
aws.amazon.com
>All but a small single-digit percentage of instances across the Amazon EC2 fleet are already protected.
As of when?
Goes on to say that the "underlying infrastructure" is protected, but OS patches are required. What does it mean that instance infrastructure is protected, but the OS is not, and which step would introduce the performance degradation?
But, perhaps that assumption was wrong and/or Amazon has another workaround.
If the hypervisor has the patch, but the Guest OS does not, it means that when the hypervisor context-switches into the Guest OS, it'll move its own kernel memory out of range of the exploit. So far so good. But the Guest OS is un-patched; when its kernel context switches into a userland process, its own kernel memory space remains available for the exploit. Thus, a patched hypervisor can protect itself, but not its guests.
I don't think updated packages are available for any of the major distributions as of now. So far I've only seen fixed packages for Amazon Linux and Google's Container-Optimized OS.