Re: How to correctly configure mitigation of CVE-2018-3646 'Foreshadow-NG (VMM)' on Xen Dom0 host?

Dario Faggioli <[email protected]> Mon, 15 Apr 2019 19:57:34 +0200
Newsgroups gmane.linux.suse.opensuse.virtual,gmane.linux.suse.security
Organization SUSE
Message-ID <[email protected]>
--=-Tq5oi9MyOFYDebaMKin2
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Mon, 2019-04-15 at 10:12 -0700, Tony Su wrote:
> Have a Q.
> Found the following artic which although is for a different CVS
> vulnerability more generally describes  ways to read proc settings
> directly to verify mitigations installed
>=20
> https://www.suse.com/support/kb/doc/?add=3D&id=3D7022937&title=3DSecurity=
+Vulnerability:+Spectre+Variant+4+(Speculative+Store+Bypass)+aka+CVE-2018-3=
639.
>=20
> Was wondering  whether there is an article similar to the one
> referenced  by "@PGnet Dev" that's a good jumping off point for other
> virtualization, specifically  KVM?
>=20
I'm not sure I have understood what you are after.

Each one of these things being --although all somewhat related--
different vulnerabilities, came out at different times, each has its
own piece of documentation (or, often, more than one!).

L1TF is the one which, it can be stated, is the most related to
virtualization, and SUSE docs for it is here (not sure this was liked
already):

https://www.suse.com/support/kb/doc/?id=3D7023077

The most authoritative source of info for KVM would be, IMO, the kernel
documentation:
https://www.kernel.org/doc/html/latest/admin-guide/l1tf.html

For Xen, I personally think the XSA is particularly well done:
https://xenbits.xen.org/xsa/advisory-273.html

But again, I'm not sure it was things like these you were actually
looking for...

Regards
--=20
Dario Faggioli, Ph.D
http://about.me/dario.faggioli
Virtualization Software Engineer
SUSE Labs, SUSE https://www.suse.com/
-------------------------------------------------------------------
<<This happens because _I_ choose it to happen!>> (Raistlin Majere)


--=-Tq5oi9MyOFYDebaMKin2
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEES5ssOj3Vhr0WPnOLFkJ4iaW4c+4FAly0xg4ACgkQFkJ4iaW4
c+44dBAA1DKN6//1/SNB0EApPzecDIIABpLM6G2b6PkDF4KjiHES9NjjVDfXYNuM
nyGxY7M8PRIkIM9kQ0B4iwyyt/dUSEdbVuFjs0DCtDE6zMpQO0tPJbsD83sX4ZnU
xOuox5kh3YU/gRCxNxWEcNkF5KC439hRbpwre+St78iXL23CucOpUldAbVUiP3RZ
fFvPWzLXMtAQi+8Y96DhRla0ZI7xowKHeGASniXzB9dl+IT5af0a8hGIdzyhzJDG
gjzYRpX/R+cB/pM7C2fROMJJnEC3zf9SJV1okgH1uiXpsunil1+RJk39UMocTZDu
nEGSrhRVho2J+rmmQYqOK0EdI0jMK9CR9tsVflwr8DQvtLh7Erf0Qbbk/IZbEEsy
7ihThmZUyYi9Sj8EXHKggV+nBLGDNxw0aA4aMXELrHqMjH5X+CNhLvKSsb6G95FG
zZGKVqPLeQoJzXerjYkzCLZ1AWuzk+zI9env2ZAA2vrIrYxy8HyV7yutuNFWVPbD
rj54eqNSCDRjJyndbsGhayB6eiAiF4omCEMBx2w9FnjLdBGMIIFCuH3+WBrB2FbD
BcmtX6YuIoXJ7kVHfGkuidl/Oii5BZkB4qAFCSSJhgdgomGutgbrxZ/uhMOKfIF7
U4bSoMaT/hA8Snb5hp2pm00RpTqKhk0UWn4YuztkfBlUXf4C684=
=jLAo
-----END PGP SIGNATURE-----

--=-Tq5oi9MyOFYDebaMKin2--