Summary: | Information disclosure with HyperThreading (CAN-2005-0109) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | kfm <kfm> |
Component: | Kernel | Assignee: | Gentoo Security <security> |
Status: | RESOLVED CANTFIX | ||
Severity: | trivial | ||
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
URL: | http://www.daemonology.net/hyperthreading-considered-harmful/ | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
kfm
2005-05-13 12:30:26 UTC
It's under review for the CVE list also (whether Linux is affected still seems unclear): http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0109 One more thing; a discussion is underway on the LKML: http://article.gmane.org/gmane.linux.kernel/302424 (seems to be some disagreement as to whether it's really an issue from the point of view of the kernel and, of course, whether it's a big deal). For the benefit of any watchers on this, here's some further discussion of the matter: http://kerneltrap.org/node/5197 Also, Con Kolivas posted a concept patch to the LKML demonstrating a "sample fix". Here's the (interesting) thread: http://article.gmane.org/gmane.linux.kernel/306979 Still waiting for upstream to decide, adding to status... I don't think upstream is able or planning to do anything about this, so closing as CANTFIX. |