• Pawan Gupta's avatar
    x86/speculation/mmio: Reuse SRBDS mitigation for SBDS · a992b8a4
    Pawan Gupta authored
    The Shared Buffers Data Sampling (SBDS) variant of Processor MMIO Stale
    Data vulnerabilities may expose RDRAND, RDSEED and SGX EGETKEY data.
    Mitigation for this is added by a microcode update.
    
    As some of the implications of SBDS are similar to SRBDS, SRBDS mitigation
    infrastructure can be leveraged by SBDS. Set X86_BUG_SRBDS and use SRBDS
    mitigation.
    
    Mitigation is enabled by default; use srbds=off to opt-out. Mitigation
    status can be checked from below file:
    
      /sys/devices/system/cpu/vulnerabilities/srbds
    Signed-off-by: default avatarPawan Gupta <pawan.kumar.gupta@linux.intel.com>
    Signed-off-by: default avatarBorislav Petkov <bp@suse.de>
    a992b8a4
common.c 60.5 KB