MDS vulnerability kernel detection and mitigation, after already having a patched bios?

Rubin Abdi <[email protected]> Sat, 13 Jan 2024 17:15:36 -0600
Newsgroups gmane.linux.hardware.thinkpad
Message-ID <CALccEhofh4A5UhYZz=pByMFjZeG=Vh_kycGXhWVJaHRLc_q4yQ@mail.gmail.com>
--===============5211300219597944553==
Content-Type: multipart/alternative; boundary="00000000000030f03b060edbf6f8"

--00000000000030f03b060edbf6f8
Content-Type: text/plain; charset="UTF-8"

TL;DR, will the kernel still detect a full positive on the
MDS vulnerability after a hypothetically patched update bios is installed?

Hello!

So today I did a Debian Sid upgrade on my ThinkPad T480s which brought in
the 6.6.9 kernel. After reboot I got some messages regarding a set of MDS
vulnerabilities:

MDS CPU bug present and SMT on, data leak possible. See
> https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html for
> more details.


After fully booting up my machine is noticeably slower, I'm assuming from
whatever mitigation to those vulnerabilities the kernel is calling.

There are 4 vulnerabilities listed on that page that I could have sworn was
patched in a bios update I did at least a year ago. Googling around I found
this Lenovo support doc about the vulnerability:

https://support.lenovo.com/us/en/product_security/ps500247-microarchitectural-data-sampling-mds-side-channel-vulnerabilities#ThinkPad

Listed there are all 4 CVEs and a link to the T480s 1.31 bios update, which
is older than the bios I was on. The annoying thing is when I look at the
release notes for 1.31 and the latest version, I see mentions of every CVE
patched except for CVE-2019-11091 - Microarchitectural Data Sampling
Uncacheable Memory (MDSUM).

I went ahead and did another update to the latest bios 1.56, released in
November, however after rebooting the kernel still reports that my machine
is vulnerable.

So my question is will the kernel still detect a full positive on the
MDS vulnerability after a hypothetically patched update bios is installed?
If so can I just safely add in the kernel options to disable the mitigation?

Thanks!

-- 
Rubin (he/him <https://en.pronouns.page/he>)
[email protected]

--00000000000030f03b060edbf6f8
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>TL;DR, will the kernel still detect a full positive o=
n the MDS=C2=A0vulnerability after a hypothetically patched update bios is =
installed?</div><div><br></div>Hello!<div><br></div><div><div>So today I di=
d a Debian Sid upgrade on my ThinkPad T480s which brought in the 6.6.9 kern=
el. After reboot I got some messages regarding a set of MDS vulnerabilities=
:</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px=
 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">MDS=
 CPU bug present and SMT on, data leak possible. See <a href=3D"https://www=
.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html">https://www.kerne=
l.org/doc/html/latest/admin-guide/hw-vuln/mds.html</a> for more details.</b=
lockquote><div><div><br></div><div>After fully booting up my machine is not=
iceably=C2=A0slower, I&#39;m assuming from whatever mitigation to those vul=
nerabilities the kernel is calling.</div><div><br></div><div>There are 4 vu=
lnerabilities=C2=A0listed on that page that I could have sworn was patched =
in a bios update I did at least a year ago. Googling around I found this Le=
novo support doc about the vulnerability:</div><div><br></div><div><a href=
=3D"https://support.lenovo.com/us/en/product_security/ps500247-microarchite=
ctural-data-sampling-mds-side-channel-vulnerabilities#ThinkPad">https://sup=
port.lenovo.com/us/en/product_security/ps500247-microarchitectural-data-sam=
pling-mds-side-channel-vulnerabilities#ThinkPad</a><br></div><div><br></div=
><div>Listed there are all 4 CVEs and a link to the T480s 1.31 bios update,=
 which is older than the bios I was on. The annoying thing is when I look a=
t the release notes for 1.31 and the latest version, I see mentions of ever=
y CVE patched except for=C2=A0CVE-2019-11091 - Microarchitectural Data Samp=
ling Uncacheable Memory (MDSUM).</div><div><br></div><div>I went ahead and =
did another update to the latest bios 1.56, released in November, however a=
fter rebooting the kernel still reports that my machine is vulnerable.</div=
><div><br></div><div>So my question is will the kernel still detect a full =
positive on the MDS=C2=A0vulnerability after a hypothetically patched updat=
e bios is installed? If so can I just safely add in the kernel options to d=
isable the=C2=A0mitigation?</div><div><br></div><div>Thanks!</div><div><br>=
</div><span class=3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr"=
 class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D"l=
tr">Rubin (<a href=3D"https://en.pronouns.page/he" target=3D"_blank">he/him=
</a>)<br><a href=3D"mailto:[email protected]" target=3D"_blank">rubin@stars=
et.net</a><br></div></div></div></div></div>

--00000000000030f03b060edbf6f8--

--===============5211300219597944553==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
The linux-thinkpad mailing list home page is at:
http://mailman.linux-thinkpad.org/mailman/listinfo/linux-thinkpad

--===============5211300219597944553==--