| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354 |
- From 5462db3d070845ecc34929b6f25a87efda023aae Mon Sep 17 00:00:00 2001
- From: Tom Lendacky <[email protected]>
- Date: Tue, 26 Dec 2017 23:43:54 -0600
- Subject: [PATCH 240/241] x86/cpu, x86/pti: Do not enable PTI on AMD processors
- MIME-Version: 1.0
- Content-Type: text/plain; charset=UTF-8
- Content-Transfer-Encoding: 8bit
- CVE-2017-5754
- AMD processors are not subject to the types of attacks that the kernel
- page table isolation feature protects against. The AMD microarchitecture
- does not allow memory references, including speculative references, that
- access higher privileged data when running in a lesser privileged mode
- when that access would result in a page fault.
- Disable page table isolation by default on AMD processors by not setting
- the X86_BUG_CPU_INSECURE feature, which controls whether X86_FEATURE_PTI
- is set.
- Signed-off-by: Tom Lendacky <[email protected]>
- Signed-off-by: Thomas Gleixner <[email protected]>
- Reviewed-by: Borislav Petkov <[email protected]>
- Cc: Dave Hansen <[email protected]>
- Cc: Andy Lutomirski <[email protected]>
- Cc: [email protected]
- Link: https://lkml.kernel.org/r/[email protected]
- (cherry picked from commit 694d99d40972f12e59a3696effee8a376b79d7c8)
- Signed-off-by: Marcelo Henrique Cerri <[email protected]>
- (cherry picked from commit 9d334f48f017b9c6457c6ba321e5a53a1cc6a5c7)
- Signed-off-by: Fabian Grünbichler <[email protected]>
- ---
- arch/x86/kernel/cpu/common.c | 4 ++--
- 1 file changed, 2 insertions(+), 2 deletions(-)
- diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c
- index 99f37d1636ff..1854dd8071a6 100644
- --- a/arch/x86/kernel/cpu/common.c
- +++ b/arch/x86/kernel/cpu/common.c
- @@ -899,8 +899,8 @@ static void __init early_identify_cpu(struct cpuinfo_x86 *c)
-
- setup_force_cpu_cap(X86_FEATURE_ALWAYS);
-
- - /* Assume for now that ALL x86 CPUs are insecure */
- - setup_force_cpu_bug(X86_BUG_CPU_INSECURE);
- + if (c->x86_vendor != X86_VENDOR_AMD)
- + setup_force_cpu_bug(X86_BUG_CPU_INSECURE);
-
- fpu__init_system(c);
- }
- --
- 2.14.2
|