Edit: I'm not sure this is right. RHEL/Centos kernel 3.10.0-693 is vulnerable but 3.10.0-693.11.6 is patched.
Edit: I'm not sure this is right. RHEL/Centos kernel 3.10.0-693 is vulnerable but 3.10.0-693.11.6 is patched.
> Over the past several days, Intel has made further progress to address the exploits known as “Spectre” and “Meltdown.”
Then it goes on to say:
> Generally speaking, the workloads that incorporate a larger number of user/kernel privilege changes and spend a significant amount of time in privileged mode will be more adversely impacted.
All of this implies that they're testing a fixed kernel.
There are also Spectre fixes landing in kernels. E.g. Linux 4.14.14 added initial retpoline support:
https://lwn.net/Articles/744621/
The current LWN has very good coverage on the latest work on Spectre/Meltdown mitigation in the kernel:
https://lwn.net/SubscriberLink/744287/d868ef1ac3f68d70/
(Posting a subscriber link in good faith. If you like such content, please subscribe to LWN.net, they are excellent!)
Which has its own performance drawbacks, but the microcode update itself has even more. And you need the microcode update for Broadwell and newer for retpolines to work.