Re: Security audit of ahci.c: Hardware trust boundaries and defensive MMIO
Aaron Rainbolt <[email protected]>
| Newsgroups | gmane.linux.debian.devel.general |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 26 May 2026 19:50:59 -0700 Michael Lazin <[email protected]> wrote: > Hello everyone, > > I have been looking into some of our lower-level hardware interfaces, > specifically auditing the AHCI driver (drivers/ata/ahci.c) through a > zero-trust hardware lens. With the rise of malicious peripherals and > PCIe-level attacks, I am concerned about the level of implicit trust > placed in MMIO responses within this driver. This sounds like something that should probably be sent to the upstream kernel developers, not to Debian... This also feels AI-generated. There have been a lot of good AI-generated vulnerability reports recently, but there have been bad ones too. The burden rests on you to verify if the potential vulns you've found with the help of AI are real vulns, and to explain to the kernel developers how those vulns work, since the upstream developers are likely flooded with work dealing with legitimate vulnerability reports on top of their usual workload. If you don't have the skill to do that, it's probably best to leave vuln hunting to others; AI generally tells multiple researchers about the same vulns at the same time, so there's a good chance anything you may have found will be found by someone else too. -- Aaron
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQS8QsiCjFi4DcDBX+Q5rdye4jrrCAUCahZotwAKCRA5rdye4jrr CK4yAP9zyf6Bv34Sv4Ed/0b6J1Z6af4Z9QFheYE6PJa6gaXHmAEA9pg9w02sE0qT 4em/6a9UqlSlibYsPJLPQha9eLYa5ws= =KNy2 -----END PGP SIGNATURE-----