MDS vulnerability kernel detection and mitigation, after already having a patched bios?
Rubin Abdi <[email protected]> Sat, 13 Jan 2024 17:15:36 -0600
| Newsgroups | gmane.linux.hardware.thinkpad |
|---|---|
| Message-ID | <CALccEhofh4A5UhYZz=pByMFjZeG=Vh_kycGXhWVJaHRLc_q4yQ@mail.gmail.com> |
--===============5211300219597944553== Content-Type: multipart/alternative; boundary="00000000000030f03b060edbf6f8" --00000000000030f03b060edbf6f8 Content-Type: text/plain; charset="UTF-8" TL;DR, will the kernel still detect a full positive on the MDS vulnerability after a hypothetically patched update bios is installed? Hello! So today I did a Debian Sid upgrade on my ThinkPad T480s which brought in the 6.6.9 kernel. After reboot I got some messages regarding a set of MDS vulnerabilities: MDS CPU bug present and SMT on, data leak possible. See > https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html for > more details. After fully booting up my machine is noticeably slower, I'm assuming from whatever mitigation to those vulnerabilities the kernel is calling. There are 4 vulnerabilities listed on that page that I could have sworn was patched in a bios update I did at least a year ago. Googling around I found this Lenovo support doc about the vulnerability: https://support.lenovo.com/us/en/product_security/ps500247-microarchitectural-data-sampling-mds-side-channel-vulnerabilities#ThinkPad Listed there are all 4 CVEs and a link to the T480s 1.31 bios update, which is older than the bios I was on. The annoying thing is when I look at the release notes for 1.31 and the latest version, I see mentions of every CVE patched except for CVE-2019-11091 - Microarchitectural Data Sampling Uncacheable Memory (MDSUM). I went ahead and did another update to the latest bios 1.56, released in November, however after rebooting the kernel still reports that my machine is vulnerable. So my question is will the kernel still detect a full positive on the MDS vulnerability after a hypothetically patched update bios is installed? If so can I just safely add in the kernel options to disable the mitigation? Thanks! -- Rubin (he/him <https://en.pronouns.page/he>) [email protected] --00000000000030f03b060edbf6f8 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>TL;DR, will the kernel still detect a full positive o= n the MDS=C2=A0vulnerability after a hypothetically patched update bios is = installed?</div><div><br></div>Hello!<div><br></div><div><div>So today I di= d a Debian Sid upgrade on my ThinkPad T480s which brought in the 6.6.9 kern= el. After reboot I got some messages regarding a set of MDS vulnerabilities= :</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px= 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">MDS= CPU bug present and SMT on, data leak possible. See <a href=3D"https://www= .kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html">https://www.kerne= l.org/doc/html/latest/admin-guide/hw-vuln/mds.html</a> for more details.</b= lockquote><div><div><br></div><div>After fully booting up my machine is not= iceably=C2=A0slower, I'm assuming from whatever mitigation to those vul= nerabilities the kernel is calling.</div><div><br></div><div>There are 4 vu= lnerabilities=C2=A0listed on that page that I could have sworn was patched = in a bios update I did at least a year ago. Googling around I found this Le= novo support doc about the vulnerability:</div><div><br></div><div><a href= =3D"https://support.lenovo.com/us/en/product_security/ps500247-microarchite= ctural-data-sampling-mds-side-channel-vulnerabilities#ThinkPad">https://sup= port.lenovo.com/us/en/product_security/ps500247-microarchitectural-data-sam= pling-mds-side-channel-vulnerabilities#ThinkPad</a><br></div><div><br></div= ><div>Listed there are all 4 CVEs and a link to the T480s 1.31 bios update,= which is older than the bios I was on. The annoying thing is when I look a= t the release notes for 1.31 and the latest version, I see mentions of ever= y CVE patched except for=C2=A0CVE-2019-11091 - Microarchitectural Data Samp= ling Uncacheable Memory (MDSUM).</div><div><br></div><div>I went ahead and = did another update to the latest bios 1.56, released in November, however a= fter rebooting the kernel still reports that my machine is vulnerable.</div= ><div><br></div><div>So my question is will the kernel still detect a full = positive on the MDS=C2=A0vulnerability after a hypothetically patched updat= e bios is installed? If so can I just safely add in the kernel options to d= isable the=C2=A0mitigation?</div><div><br></div><div>Thanks!</div><div><br>= </div><span class=3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr"= class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D"l= tr">Rubin (<a href=3D"https://en.pronouns.page/he" target=3D"_blank">he/him= </a>)<br><a href=3D"mailto:[email protected]" target=3D"_blank">rubin@stars= et.net</a><br></div></div></div></div></div> --00000000000030f03b060edbf6f8-- --===============5211300219597944553== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- The linux-thinkpad mailing list home page is at: http://mailman.linux-thinkpad.org/mailman/listinfo/linux-thinkpad --===============5211300219597944553==--