Linux 7.4 To Land New BTB CTX Isolation Feature Of AMD Zen 6

Linux 7.4 To Land New BTB CTX Isolation Feature Of AMD Zen 6

The Linux 7.4 kernel is set to introduce support for a new AMD Zen 6 security feature. Adding to the Zen 6 related patches queuing up ahead of the Linux 7.4 merge window later this month is enabling support for the new Branch Target Buffer Context "BTB CTX" Isolation feature. BTB CTX Isolation is a new security defense against SRSO, the Speculative Return Stack Overflow vulnerability that affected Zen 1 to Zen 4 CPUs. BTB CTX Isolation will isolate the different user/kernel and guest/host contexts from one another. This patch queued now into tip/tip.git's "x86/bugs" Git branch adapts the AMD SRSO mitigation for this new Zen 6 capability: "Zen6 has BTB protection which isolates the different contexts (user/kernel, guest/host) from one another. This makes the SafeRET mitigation there unnecessary leaving the user/user and guest/guest attack vectors open, whose protection is handled by the Spectre v2 mitigation setting to do IBPB on a context switch. Detect that setting and report it with a new mitigation string." With the patch in a TIP Git branch ahead of the Linux 7.4 merge window opening later this month, it should be submitted for that next kernel version. Linux 7.4 is looking to be an important kernel overall for Zen 6 enablement, especially on the Ryzen client side with a number of patches landing while for the 6th Gen EPYC "Venice" servers we've already been seeing work there the past several kernel cycle.

Original Source

Read the full article at Phoronix →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.