В ядре Linux устранена следующая уязвимость:
iommu/vt-d: принудительный запрос ACS, когда tboot включен.
На данный момент условия запроса ACS в define_intel_iommu()
не включайте tboot, что может привести к неправильной настройке ACS
отключен (например, по выбору пользователя), в то время как iommu позже принудительно включается
tboot_force_iommu().
Исправьте это, проверив tboot в обнаружении_intel_iommu().
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enabled Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due to user opts) while iommu is later forced on by tboot_force_iommu(). Fix it by checking tboot in detect_intel_iommu().
Характеристики атаки
Последствия
Строка CVSS v3.1