ACK: [UBUNTU Focal, Jammy, Kinetic, Lunar, OEM-5.14, OEM-5.17, OEM-6.0 0/1] CVE-2022-2196

Cengiz Can cengiz.can at canonical.com
Sat Feb 11 10:19:35 UTC 2023


On 23-02-10 15:21:56, Thadeu Lima de Souza Cascardo wrote:
> [Impact]
> An L2 guest could do an spectre-v2 attack on an L1 guest if that guest assumes
> IBRS or eIBRS can be used to isolate between them, while it cannot. L0 needs to
> issue an IBPB in these cases.
> 
> [Potential impact]
> Systems using nested guests might have a performance impact.
> 
> Jim Mattson (1):
>   KVM: VMX: Execute IBPB on emulated VM-exit when guest has IBRS

Acked-by: Cengiz Can <cengiz.can at canonical.com>

> 
>  arch/x86/kvm/vmx/nested.c | 11 +++++++++++
>  arch/x86/kvm/vmx/vmx.c    |  6 ++++--
>  2 files changed, 15 insertions(+), 2 deletions(-)
> 
> -- 
> 2.34.1
> 
> 
> -- 
> kernel-team mailing list
> kernel-team at lists.ubuntu.com
> https://lists.ubuntu.com/mailman/listinfo/kernel-team



More information about the kernel-team mailing list