]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/commit
x86/speculation: Include unprivileged eBPF status in Spectre v2 mitigation reporting
authorJosh Poimboeuf <jpoimboe@redhat.com>
Mon, 4 Apr 2022 20:16:34 +0000 (17:16 -0300)
committerStefan Bader <stefan.bader@canonical.com>
Thu, 14 Apr 2022 09:31:51 +0000 (11:31 +0200)
commitd7e01af4a31eef7aced7256fa34676c42d70d48d
treebe455384ad370e9996f2e5f75f9c89fa2816c153
parent04545fdde026686eaba79f0ea647895072831d5d
x86/speculation: Include unprivileged eBPF status in Spectre v2 mitigation reporting

commit 44a3918c8245ab10c6c9719dd12e7a8d291980d8 upstream.

With unprivileged eBPF enabled, eIBRS (without retpoline) is vulnerable
to Spectre v2 BHB-based attacks.

When both are enabled, print a warning message and report it in the
'spectre_v2' sysfs vulnerabilities file.

Signed-off-by: Josh Poimboeuf <jpoimboe@redhat.com>
Signed-off-by: Borislav Petkov <bp@suse.de>
Reviewed-by: Thomas Gleixner <tglx@linutronix.de>
[fllinden@amazon.com: backported to 5.4]
Signed-off-by: Frank van der Linden <fllinden@amazon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
CVE-2022-0001
(cherry picked from commit 1e47ab3df908bbe1b6114374003c7a070ef35f01 linux-5.4.y)
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@canonical.com>
Acked-by: Stefan Bader <stefan.bader@canonical.com>
Acked-by: Tim Gardner <tim.gardner@canonical.com>
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>
arch/x86/kernel/cpu/bugs.c
include/linux/bpf.h
kernel/sysctl.c