[coreboot - Bug #576] GPIO locking is broken on Kaby Lake and possibly other platforms

Mate Kukri via coreboot <[email protected]>
Newsgroups gmane.linux.bios
Message-ID <[email protected]>
Issue #576 has been updated by Mate Kukri.


Just noticing this many months later, it seems like Intel did public guidance about this in February 2026: https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/gpio-configuration-best-practices.html
Intel acknowledged the existence of TPM GPIO fail in public almost 2 years after publication, amazing, just noticing this from february

----------------------------------------
Bug #576: GPIO locking is broken on Kaby Lake and possibly other platforms
https://ticket.coreboot.org/issues/576#change-2398

* Author: Mate Kukri
* Status: New
* Priority: Normal
* Target version: none
* Start date: 2025-01-30
----------------------------------------
Many supported Kaby Lake boards (and possibly newer platforms as well) are vulnerable to [TPM GPIO reset attacks](https://mkukri.xyz/2024/06/01/tpm-gpio-fail.html).

Trying to fix this by marking the affected GPIOs as locked in gpio.h and even also selecting `SOC_INTEL_COMMON_BLOCK_SMM_LOCK_GPIO_PADS` does not work.

This was discovered last year and briefly discussed on #coreboot, but it came up again on the Heads matrix group in relation to supporting the TPM on the in-progress ThinkPad T480 port.



-- 
You have received this notification because you have either subscribed to it, or are involved in it.
To change your notification preferences, please click here: https://ticket.coreboot.org/my/account
_______________________________________________
coreboot mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.