search for: gatget

Displaying 3 results from an estimated 3 matches for "gatget".

Did you mean: gadget
2019 Sep 11
2
[PATCH v2] vhost: block speculation of translated descriptors
On Wed, Sep 11, 2019 at 02:33:16PM +0200, Michal Hocko wrote: > On Wed 11-09-19 08:25:03, Michael S. Tsirkin wrote: > > On Wed, Sep 11, 2019 at 02:16:28PM +0200, Michal Hocko wrote: > > > On Wed 11-09-19 08:10:00, Michael S. Tsirkin wrote: > > > > iovec addresses coming from vhost are assumed to be > > > > pre-validated, but in fact can be speculated to a
2019 Sep 11
2
[PATCH v2] vhost: block speculation of translated descriptors
On Wed, Sep 11, 2019 at 02:33:16PM +0200, Michal Hocko wrote: > On Wed 11-09-19 08:25:03, Michael S. Tsirkin wrote: > > On Wed, Sep 11, 2019 at 02:16:28PM +0200, Michal Hocko wrote: > > > On Wed 11-09-19 08:10:00, Michael S. Tsirkin wrote: > > > > iovec addresses coming from vhost are assumed to be > > > > pre-validated, but in fact can be speculated to a
2019 Sep 11
0
[PATCH v2] vhost: block speculation of translated descriptors
...ere in practice? > > > > not marked for stable but it went in. At least to 4.4. > > So I guess the answer is I don't know. If you feel it's > justified, then sure, feel free to forward. Well, that obviously depends on you as a maintainer but the point is that spectre gatgets are quite hard to find. There is a smack check AFAIK but that generates quite some false possitives and it is PITA to crawl through those. If you want an interesting (I am not saying vulnerable on purpose) gatget then it would be great to mark it for stable so all stable consumers (disclaimer: I a...