€•'ïŒsphinx.addnodes”Œdocument”“”)�”}”(Œ rawsource”Œ”Œchildren”]”(Œ translations”Œ LanguagesNode”“”)�”}”(hhh]”(hŒ pending_xref”“”)�”}”(hhh]”Œdocutils.nodes”ŒText”“”ŒChinese (Simplified)”…”�”}”Œparent”hsbaŒ attributes”}”(Œids”]”Œclasses”]”Œnames”]”Œdupnames”]”Œbackrefs”]”Œ refdomain”Œstd”Œreftype”Œdoc”Œ reftarget”Œ+/translations/zh_CN/admin-guide/hw-vuln/mds”Œmodname”NŒ classname”NŒ refexplicit”ˆuŒtagname”hhh ubh)�”}”(hhh]”hŒChinese (Traditional)”…”�”}”hh2sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ+/translations/zh_TW/admin-guide/hw-vuln/mds”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒItalian”…”�”}”hhFsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ+/translations/it_IT/admin-guide/hw-vuln/mds”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒJapanese”…”�”}”hhZsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ+/translations/ja_JP/admin-guide/hw-vuln/mds”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒKorean”…”�”}”hhnsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ+/translations/ko_KR/admin-guide/hw-vuln/mds”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒPortuguese (Brazilian)”…”�”}”hh‚sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ+/translations/pt_BR/admin-guide/hw-vuln/mds”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒSpanish”…”�”}”hh–sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ+/translations/sp_SP/admin-guide/hw-vuln/mds”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubeh}”(h]”h ]”h"]”h$]”h&]”Œcurrent_language”ŒEnglish”uh1h hhŒ _document”hŒsource”NŒline”NubhŒsection”“”)�”}”(hhh]”(hŒtitle”“”)�”}”(hŒ&MDS - Microarchitectural Data Sampling”h]”hŒ&MDS - Microarchitectural Data Sampling”…”�”}”(hh¼h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhh·h²hh³ŒE/var/lib/git/docbuild/linux/Documentation/admin-guide/hw-vuln/mds.rst”h´KubhŒ paragraph”“”)�”}”(hŒ¥Microarchitectural Data Sampling is a hardware vulnerability which allows unprivileged speculative access to data which is available in various CPU internal buffers.”h]”hŒ¥Microarchitectural Data Sampling is a hardware vulnerability which allows unprivileged speculative access to data which is available in various CPU internal buffers.”…”�”}”(hhÍh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Khh·h²hubh¶)�”}”(hhh]”(h»)�”}”(hŒAffected processors”h]”hŒAffected processors”…”�”}”(hhÞh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhhÛh²hh³hÊh´K ubhÌ)�”}”(hŒaThis vulnerability affects a wide range of Intel processors. The vulnerability is not present on:”h]”hŒaThis vulnerability affects a wide range of Intel processors. The vulnerability is not present on:”…”�”}”(hhìh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K hhÛh²hubhŒ block_quote”“”)�”}”(hX - Processors from AMD, Centaur and other non Intel vendors - Older processor models, where the CPU family is < 6 - Some Atoms (Bonnell, Saltwell, Goldmont, GoldmontPlus) - Intel processors which have the ARCH_CAP_MDS_NO bit set in the IA32_ARCH_CAPABILITIES MSR. ”h]”hŒ bullet_list”“”)�”}”(hhh]”(hŒ list_item”“”)�”}”(hŒ9Processors from AMD, Centaur and other non Intel vendors ”h]”hÌ)�”}”(hŒ8Processors from AMD, Centaur and other non Intel vendors”h]”hŒ8Processors from AMD, Centaur and other non Intel vendors”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Khjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hŒ4Older processor models, where the CPU family is < 6 ”h]”hÌ)�”}”(hŒ3Older processor models, where the CPU family is < 6”h]”hŒ3Older processor models, where the CPU family is < 6”…”�”}”(hj#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Khjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hŒ7Some Atoms (Bonnell, Saltwell, Goldmont, GoldmontPlus) ”h]”hÌ)�”}”(hŒ6Some Atoms (Bonnell, Saltwell, Goldmont, GoldmontPlus)”h]”hŒ6Some Atoms (Bonnell, Saltwell, Goldmont, GoldmontPlus)”…”�”}”(hj;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Khj7ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hŒ[Intel processors which have the ARCH_CAP_MDS_NO bit set in the IA32_ARCH_CAPABILITIES MSR. ”h]”hÌ)�”}”(hŒZIntel processors which have the ARCH_CAP_MDS_NO bit set in the IA32_ARCH_CAPABILITIES MSR.”h]”hŒZIntel processors which have the ARCH_CAP_MDS_NO bit set in the IA32_ARCH_CAPABILITIES MSR.”…”�”}”(hjSh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KhjOubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubeh}”(h]”h ]”h"]”h$]”h&]”Œbullet”Œ-”uh1jh³hÊh´Khhüubah}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´KhhÛh²hubhÌ)�”}”(hŒyWhether a processor is affected or not can be read out from the MDS vulnerability file in sysfs. See :ref:`mds_sys_info`.”h]”(hŒeWhether a processor is affected or not can be read out from the MDS vulnerability file in sysfs. See ”…”�”}”(hjuh²hh³Nh´Nubh)�”}”(hŒ:ref:`mds_sys_info`”h]”hŒinline”“”)�”}”(hjh]”hŒ mds_sys_info”…”�”}”(hjƒh²hh³Nh´Nubah}”(h]”h ]”(Œxref”Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hj}ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”Œadmin-guide/hw-vuln/mds”Œ refdomain”jŽŒreftype”Œref”Œ refexplicit”‰Œrefwarn”ˆŒ reftarget”Œ mds_sys_info”uh1hh³hÊh´KhjuubhŒ.”…”�”}”(hjuh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KhhÛh²hubhÌ)�”}”(hŒœNot all processors are affected by all variants of MDS, but the mitigation is identical for all of them so the kernel treats them as a single vulnerability.”h]”hŒœNot all processors are affected by all variants of MDS, but the mitigation is identical for all of them so the kernel treats them as a single vulnerability.”…”�”}”(hj¬h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KhhÛh²hubeh}”(h]”Œaffected-processors”ah ]”h"]”Œaffected processors”ah$]”h&]”uh1hµhh·h²hh³hÊh´K ubh¶)�”}”(hhh]”(h»)�”}”(hŒ Related CVEs”h]”hŒ Related CVEs”…”�”}”(hjÅh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjÂh²hh³hÊh´KubhÌ)�”}”(hŒ?The following CVE entries are related to the MDS vulnerability:”h]”hŒ?The following CVE entries are related to the MDS vulnerability:”…”�”}”(hjÓh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K!hjÂh²hubhû)�”}”(hX¬============== ===== =================================================== CVE-2018-12126 MSBDS Microarchitectural Store Buffer Data Sampling CVE-2018-12130 MFBDS Microarchitectural Fill Buffer Data Sampling CVE-2018-12127 MLPDS Microarchitectural Load Port Data Sampling CVE-2019-11091 MDSUM Microarchitectural Data Sampling Uncacheable Memory ============== ===== =================================================== ”h]”hŒtable”“”)�”}”(hhh]”hŒtgroup”“”)�”}”(hhh]”(hŒcolspec”“”)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jïhjìubjð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jïhjìubjð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”K3uh1jïhjìubhŒtbody”“”)�”}”(hhh]”(hŒrow”“”)�”}”(hhh]”(hŒentry”“”)�”}”(hhh]”hÌ)�”}”(hŒCVE-2018-12126”h]”hŒCVE-2018-12126”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K$hjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”hÌ)�”}”(hŒMSBDS”h]”hŒMSBDS”…”�”}”(hj5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K$hj2ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”hÌ)�”}”(hŒ-Microarchitectural Store Buffer Data Sampling”h]”hŒ-Microarchitectural Store Buffer Data Sampling”…”�”}”(hjLh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K$hjIubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒCVE-2018-12130”h]”hŒCVE-2018-12130”…”�”}”(hjlh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K%hjiubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjfubj)�”}”(hhh]”hÌ)�”}”(hŒMFBDS”h]”hŒMFBDS”…”�”}”(hjƒh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K%hj€ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjfubj)�”}”(hhh]”hÌ)�”}”(hŒ,Microarchitectural Fill Buffer Data Sampling”h]”hŒ,Microarchitectural Fill Buffer Data Sampling”…”�”}”(hjšh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K%hj—ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjfubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒCVE-2018-12127”h]”hŒCVE-2018-12127”…”�”}”(hjºh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K&hj·ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj´ubj)�”}”(hhh]”hÌ)�”}”(hŒMLPDS”h]”hŒMLPDS”…”�”}”(hjÑh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K&hjÎubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj´ubj)�”}”(hhh]”hÌ)�”}”(hŒ*Microarchitectural Load Port Data Sampling”h]”hŒ*Microarchitectural Load Port Data Sampling”…”�”}”(hjèh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K&hjåubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj´ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒCVE-2019-11091”h]”hŒCVE-2019-11091”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K'hjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”hÌ)�”}”(hŒMDSUM”h]”hŒMDSUM”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K'hjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”hÌ)�”}”(hŒ3Microarchitectural Data Sampling Uncacheable Memory”h]”hŒ3Microarchitectural Data Sampling Uncacheable Memory”…”�”}”(hj6h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K'hj3ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjìubeh}”(h]”h ]”h"]”h$]”h&]”Œcols”Kuh1jêhjçubah}”(h]”h ]”h"]”h$]”h&]”uh1jåhjáubah}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´K#hjÂh²hubeh}”(h]”Œ related-cves”ah ]”h"]”Œ related cves”ah$]”h&]”uh1hµhh·h²hh³hÊh´Kubh¶)�”}”(hhh]”(h»)�”}”(hŒProblem”h]”hŒProblem”…”�”}”(hjth²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjqh²hh³hÊh´K+ubhÌ)�”}”(hŒÏWhen performing store, load, L1 refill operations, processors write data into temporary microarchitectural structures (buffers). The data in the buffer can be forwarded to load operations as an optimization.”h]”hŒÏWhen performing store, load, L1 refill operations, processors write data into temporary microarchitectural structures (buffers). The data in the buffer can be forwarded to load operations as an optimization.”…”�”}”(hj‚h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K-hjqh²hubhÌ)�”}”(hXôUnder certain conditions, usually a fault/assist caused by a load operation, data unrelated to the load memory address can be speculatively forwarded from the buffers. Because the load operation causes a fault or assist and its result will be discarded, the forwarded data will not cause incorrect program execution or state changes. But a malicious operation may be able to forward this speculative data to a disclosure gadget which allows in turn to infer the value via a cache side channel attack.”h]”hXôUnder certain conditions, usually a fault/assist caused by a load operation, data unrelated to the load memory address can be speculatively forwarded from the buffers. Because the load operation causes a fault or assist and its result will be discarded, the forwarded data will not cause incorrect program execution or state changes. But a malicious operation may be able to forward this speculative data to a disclosure gadget which allows in turn to infer the value via a cache side channel attack.”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K1hjqh²hubhÌ)�”}”(hŒiBecause the buffers are potentially shared between Hyper-Threads cross Hyper-Thread attacks are possible.”h]”hŒiBecause the buffers are potentially shared between Hyper-Threads cross Hyper-Thread attacks are possible.”…”�”}”(hjžh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K9hjqh²hubhÌ)�”}”(hŒ„Deeper technical information is available in the MDS specific x86 architecture section: :ref:`Documentation/arch/x86/mds.rst `.”h]”(hŒXDeeper technical information is available in the MDS specific x86 architecture section: ”…”�”}”(hj¬h²hh³Nh´Nubh)�”}”(hŒ+:ref:`Documentation/arch/x86/mds.rst `”h]”j‚)�”}”(hj¶h]”hŒDocumentation/arch/x86/mds.rst”…”�”}”(hj¸h²hh³Nh´Nubah}”(h]”h ]”(j�Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hj´ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”jšŒ refdomain”jÂŒreftype”Œref”Œ refexplicit”ˆŒrefwarn”ˆj Œmds”uh1hh³hÊh´KsŒexpect_referenced_by_id”}”jIj>subh¶)�”}”(hhh]”(h»)�”}”(hŒMitigation mechanism”h]”hŒMitigation mechanism”…”�”}”(hjúh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj÷h²hh³hÊh´K…ubhÌ)�”}”(hŒYThe kernel detects the affected CPUs and the presence of the microcode which is required.”h]”hŒYThe kernel detects the affected CPUs and the presence of the microcode which is required.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K‡hj÷h²hubhÌ)�”}”(hŒçIf a CPU is affected and the microcode is available, then the kernel enables the mitigation by default. The mitigation can be controlled at boot time via a kernel command line option. See :ref:`mds_mitigation_control_command_line`.”h]”(hŒ¼If a CPU is affected and the microcode is available, then the kernel enables the mitigation by default. The mitigation can be controlled at boot time via a kernel command line option. See ”…”�”}”(hjh²hh³Nh´Nubh)�”}”(hŒ*:ref:`mds_mitigation_control_command_line`”h]”j‚)�”}”(hj h]”hŒ#mds_mitigation_control_command_line”…”�”}”(hj"h²hh³Nh´Nubah}”(h]”h ]”(j�Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hjubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”jšŒ refdomain”j,Œreftype”Œref”Œ refexplicit”‰Œrefwarn”ˆj Œ#mds_mitigation_control_command_line”uh1hh³hÊh´KŠhjubhŒ.”…”�”}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KŠhj÷h²hubj=)�”}”(hŒ.. _cpu_buffer_clear:”h]”h}”(h]”h ]”h"]”h$]”h&]”jHŒcpu-buffer-clear”uh1j<h´K�hj÷h²hh³hÊubh¶)�”}”(hhh]”(h»)�”}”(hŒCPU buffer clearing”h]”hŒCPU buffer clearing”…”�”}”(hjVh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjSh²hh³hÊh´K’ubhû)�”}”(hXÈThe mitigation for MDS clears the affected CPU buffers on return to user space and when entering a guest. If SMT is enabled it also clears the buffers on idle entry when the CPU is only affected by MSBDS and not any other MDS variant, because the other variants cannot be protected against cross Hyper-Thread attacks. For CPUs which are only affected by MSBDS the user space, guest and idle transition mitigations are sufficient and SMT is not affected. ”h]”(hÌ)�”}”(hŒiThe mitigation for MDS clears the affected CPU buffers on return to user space and when entering a guest.”h]”hŒiThe mitigation for MDS clears the affected CPU buffers on return to user space and when entering a guest.”…”�”}”(hjhh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K”hjdubhÌ)�”}”(hŒÓIf SMT is enabled it also clears the buffers on idle entry when the CPU is only affected by MSBDS and not any other MDS variant, because the other variants cannot be protected against cross Hyper-Thread attacks.”h]”hŒÓIf SMT is enabled it also clears the buffers on idle entry when the CPU is only affected by MSBDS and not any other MDS variant, because the other variants cannot be protected against cross Hyper-Thread attacks.”…”�”}”(hjvh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K—hjdubhÌ)�”}”(hŒ‡For CPUs which are only affected by MSBDS the user space, guest and idle transition mitigations are sufficient and SMT is not affected.”h]”hŒ‡For CPUs which are only affected by MSBDS the user space, guest and idle transition mitigations are sufficient and SMT is not affected.”…”�”}”(hj„h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K›hjdubeh}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´K”hjSh²hubj=)�”}”(hŒ.. _virt_mechanism:”h]”h}”(h]”h ]”h"]”h$]”h&]”jHŒvirt-mechanism”uh1j<h´KžhjSh²hh³hÊubeh}”(h]”(Œcpu-buffer-clearing”jReh ]”h"]”(Œcpu buffer clearing”Œcpu_buffer_clear”eh$]”h&]”uh1hµhj÷h²hh³hÊh´K’jó}”j©jHsjõ}”jRjHsubh¶)�”}”(hhh]”(h»)�”}”(hŒVirtualization mitigation”h]”hŒVirtualization mitigation”…”�”}”(hj±h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj®h²hh³hÊh´K¡ubhû)�”}”(hX¨The protection for host to guest transition depends on the L1TF vulnerability of the CPU: - CPU is affected by L1TF: If the L1D flush mitigation is enabled and up to date microcode is available, the L1D flush mitigation is automatically protecting the guest transition. If the L1D flush mitigation is disabled then the MDS mitigation is invoked explicit when the host MDS mitigation is enabled. For details on L1TF and virtualization see: :ref:`Documentation/admin-guide/hw-vuln//l1tf.rst `. - CPU is not affected by L1TF: CPU buffers are flushed before entering the guest when the host MDS mitigation is enabled. The resulting MDS protection matrix for the host to guest transition: ============ ===== ============= ============ ================= L1TF MDS VMX-L1FLUSH Host MDS MDS-State Don't care No Don't care N/A Not affected Yes Yes Disabled Off Vulnerable Yes Yes Disabled Full Mitigated Yes Yes Enabled Don't care Mitigated No Yes N/A Off Vulnerable No Yes N/A Full Mitigated ============ ===== ============= ============ ================= This only covers the host to guest transition, i.e. prevents leakage from host to guest, but does not protect the guest internally. Guests need to have their own protections. ”h]”(hÌ)�”}”(hŒYThe protection for host to guest transition depends on the L1TF vulnerability of the CPU:”h]”hŒYThe protection for host to guest transition depends on the L1TF vulnerability of the CPU:”…”�”}”(hjÃh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K£hj¿ubj)�”}”(hhh]”(j)�”}”(hX«CPU is affected by L1TF: If the L1D flush mitigation is enabled and up to date microcode is available, the L1D flush mitigation is automatically protecting the guest transition. If the L1D flush mitigation is disabled then the MDS mitigation is invoked explicit when the host MDS mitigation is enabled. For details on L1TF and virtualization see: :ref:`Documentation/admin-guide/hw-vuln//l1tf.rst `. ”h]”(hÌ)�”}”(hŒCPU is affected by L1TF:”h]”hŒCPU is affected by L1TF:”…”�”}”(hjØh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¦hjÔubhÌ)�”}”(hŒ˜If the L1D flush mitigation is enabled and up to date microcode is available, the L1D flush mitigation is automatically protecting the guest transition.”h]”hŒ˜If the L1D flush mitigation is enabled and up to date microcode is available, the L1D flush mitigation is automatically protecting the guest transition.”…”�”}”(hjæh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¨hjÔubhÌ)�”}”(hŒ|If the L1D flush mitigation is disabled then the MDS mitigation is invoked explicit when the host MDS mitigation is enabled.”h]”hŒ|If the L1D flush mitigation is disabled then the MDS mitigation is invoked explicit when the host MDS mitigation is enabled.”…”�”}”(hjôh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¬hjÔubhÌ)�”}”(hŒxFor details on L1TF and virtualization see: :ref:`Documentation/admin-guide/hw-vuln//l1tf.rst `.”h]”(hŒ,For details on L1TF and virtualization see: ”…”�”}”(hjh²hh³Nh´Nubh)�”}”(hŒK:ref:`Documentation/admin-guide/hw-vuln//l1tf.rst `”h]”j‚)�”}”(hj h]”hŒ+Documentation/admin-guide/hw-vuln//l1tf.rst”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”(j�Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hj ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”jšŒ refdomain”jŒreftype”Œref”Œ refexplicit”ˆŒrefwarn”ˆj Œmitigation_control_kvm”uh1hh³hÊh´K¯hjubhŒ.”…”�”}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¯hjÔubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjÑubj)�”}”(hŒyCPU is not affected by L1TF: CPU buffers are flushed before entering the guest when the host MDS mitigation is enabled. ”h]”(hÌ)�”}”(hŒCPU is not affected by L1TF:”h]”hŒCPU is not affected by L1TF:”…”�”}”(hj>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K²hj:ubhÌ)�”}”(hŒZCPU buffers are flushed before entering the guest when the host MDS mitigation is enabled.”h]”hŒZCPU buffers are flushed before entering the guest when the host MDS mitigation is enabled.”…”�”}”(hjLh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K´hj:ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjÑubeh}”(h]”h ]”h"]”h$]”h&]”jmjnuh1jh³hÊh´K¦hj¿ubhÌ)�”}”(hŒEThe resulting MDS protection matrix for the host to guest transition:”h]”hŒEThe resulting MDS protection matrix for the host to guest transition:”…”�”}”(hjfh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K·hj¿ubjæ)�”}”(hhh]”jë)�”}”(hhh]”(jð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”K uh1jïhjwubjð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jïhjwubjð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”K uh1jïhjwubjð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”K uh1jïhjwubjð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”Kuh1jïhjwubj)�”}”(hhh]”(j)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒL1TF”h]”hŒL1TF”…”�”}”(hjµh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kºhj²ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj¯ubj)�”}”(hhh]”hÌ)�”}”(hŒMDS”h]”hŒMDS”…”�”}”(hjÌh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KºhjÉubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj¯ubj)�”}”(hhh]”hÌ)�”}”(hŒ VMX-L1FLUSH”h]”hŒ VMX-L1FLUSH”…”�”}”(hjãh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kºhjàubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj¯ubj)�”}”(hhh]”hÌ)�”}”(hŒHost MDS”h]”hŒHost MDS”…”�”}”(hjúh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kºhj÷ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj¯ubj)�”}”(hhh]”hÌ)�”}”(hŒ MDS-State”h]”hŒ MDS-State”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kºhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj¯ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj¬ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒ Don't care”h]”hŒ Don’t care”…”�”}”(hj1 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¼hj. ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ ubj)�”}”(hhh]”hÌ)�”}”(hŒNo”h]”hŒNo”…”�”}”(hjH h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¼hjE ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ ubj)�”}”(hhh]”hÌ)�”}”(hŒ Don't care”h]”hŒ Don’t care”…”�”}”(hj_ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¼hj\ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ ubj)�”}”(hhh]”hÌ)�”}”(hŒN/A”h]”hŒN/A”…”�”}”(hjv h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¼hjs ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ ubj)�”}”(hhh]”hÌ)�”}”(hŒ Not affected”h]”hŒ Not affected”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¼hjŠ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj¬ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hj­ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¾hjª ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj§ ubj)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hjÄ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¾hjÁ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj§ ubj)�”}”(hhh]”hÌ)�”}”(hŒDisabled”h]”hŒDisabled”…”�”}”(hjÛ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¾hjØ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj§ ubj)�”}”(hhh]”hÌ)�”}”(hŒOff”h]”hŒOff”…”�”}”(hjò h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¾hjï ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj§ ubj)�”}”(hhh]”hÌ)�”}”(hŒ Vulnerable”h]”hŒ Vulnerable”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´K¾hj ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj§ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj¬ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hj) h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÀhj& ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj# ubj)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hj@ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÀhj= ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj# ubj)�”}”(hhh]”hÌ)�”}”(hŒDisabled”h]”hŒDisabled”…”�”}”(hjW h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÀhjT ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj# ubj)�”}”(hhh]”hÌ)�”}”(hŒFull”h]”hŒFull”…”�”}”(hjn h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÀhjk ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj# ubj)�”}”(hhh]”hÌ)�”}”(hŒ Mitigated”h]”hŒ Mitigated”…”�”}”(hj… h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÀhj‚ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj# ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj¬ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hj¥ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÂhj¢ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjŸ ubj)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hj¼ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÂhj¹ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjŸ ubj)�”}”(hhh]”hÌ)�”}”(hŒEnabled”h]”hŒEnabled”…”�”}”(hjÓ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÂhjÐ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjŸ ubj)�”}”(hhh]”hÌ)�”}”(hŒ Don't care”h]”hŒ Don’t care”…”�”}”(hjê h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÂhjç ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjŸ ubj)�”}”(hhh]”hÌ)�”}”(hŒ Mitigated”h]”hŒ Mitigated”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÂhjþ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjŸ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj¬ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒNo”h]”hŒNo”…”�”}”(hj! h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÄhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubj)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hj8 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÄhj5 ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubj)�”}”(hhh]”hÌ)�”}”(hŒN/A”h]”hŒN/A”…”�”}”(hjO h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÄhjL ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubj)�”}”(hhh]”hÌ)�”}”(hŒOff”h]”hŒOff”…”�”}”(hjf h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÄhjc ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubj)�”}”(hhh]”hÌ)�”}”(hŒ Vulnerable”h]”hŒ Vulnerable”…”�”}”(hj} h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÄhjz ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj¬ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒNo”h]”hŒNo”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÆhjš ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj— ubj)�”}”(hhh]”hÌ)�”}”(hŒYes”h]”hŒYes”…”�”}”(hj´ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÆhj± ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj— ubj)�”}”(hhh]”hÌ)�”}”(hŒN/A”h]”hŒN/A”…”�”}”(hjË h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÆhjÈ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj— ubj)�”}”(hhh]”hÌ)�”}”(hŒFull”h]”hŒFull”…”�”}”(hjâ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÆhjß ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj— ubj)�”}”(hhh]”hÌ)�”}”(hŒ Mitigated”h]”hŒ Mitigated”…”�”}”(hjù h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÆhjö ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj— ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj¬ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjwubeh}”(h]”h ]”h"]”h$]”h&]”Œcols”Kuh1jêhjtubah}”(h]”h ]”h"]”h$]”h&]”uh1jåhj¿ubhÌ)�”}”(hŒ®This only covers the host to guest transition, i.e. prevents leakage from host to guest, but does not protect the guest internally. Guests need to have their own protections.”h]”hŒ®This only covers the host to guest transition, i.e. prevents leakage from host to guest, but does not protect the guest internally. Guests need to have their own protections.”…”�”}”(hj& h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÉhj¿ubeh}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´K£hj®h²hubj=)�”}”(hŒ .. _xeon_phi:”h]”h}”(h]”h ]”h"]”h$]”h&]”jHŒxeon-phi”uh1j<h´KÍhj®h²hh³hÊubeh}”(h]”(Œvirtualization-mitigation”j¢eh ]”h"]”(Œvirtualization mitigation”Œvirt_mechanism”eh$]”h&]”uh1hµhj÷h²hh³hÊh´K¡jó}”jK j˜sjõ}”j¢j˜subh¶)�”}”(hhh]”(h»)�”}”(hŒ XEON PHI specific considerations”h]”hŒ XEON PHI specific considerations”…”�”}”(hjS h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjP h²hh³hÊh´KÐubhû)�”}”(hX4The XEON PHI processor family is affected by MSBDS which can be exploited cross Hyper-Threads when entering idle states. Some XEON PHI variants allow to use MWAIT in user space (Ring 3) which opens an potential attack vector for malicious user space. The exposure can be disabled on the kernel command line with the 'ring3mwait=disable' command line option. XEON PHI is not affected by the other MDS variants and MSBDS is mitigated before the CPU enters an idle state. As XEON PHI is not affected by L1TF either disabling SMT is not required for full protection. ”h]”(hÌ)�”}”(hXeThe XEON PHI processor family is affected by MSBDS which can be exploited cross Hyper-Threads when entering idle states. Some XEON PHI variants allow to use MWAIT in user space (Ring 3) which opens an potential attack vector for malicious user space. The exposure can be disabled on the kernel command line with the 'ring3mwait=disable' command line option.”h]”hXiThe XEON PHI processor family is affected by MSBDS which can be exploited cross Hyper-Threads when entering idle states. Some XEON PHI variants allow to use MWAIT in user space (Ring 3) which opens an potential attack vector for malicious user space. The exposure can be disabled on the kernel command line with the ‘ring3mwait=disable’ command line option.”…”�”}”(hje h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KÒhja ubhÌ)�”}”(hŒÌXEON PHI is not affected by the other MDS variants and MSBDS is mitigated before the CPU enters an idle state. As XEON PHI is not affected by L1TF either disabling SMT is not required for full protection.”h]”hŒÌXEON PHI is not affected by the other MDS variants and MSBDS is mitigated before the CPU enters an idle state. As XEON PHI is not affected by L1TF either disabling SMT is not required for full protection.”…”�”}”(hjs h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KØhja ubeh}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´KÒhjP h²hubj=)�”}”(hŒ.. _mds_smt_control:”h]”h}”(h]”h ]”h"]”h$]”h&]”jHŒmds-smt-control”uh1j<h´KÜhjP h²hh³hÊubeh}”(h]”(Œ xeon-phi-specific-considerations”jD eh ]”h"]”(Œ xeon phi specific considerations”Œxeon_phi”eh$]”h&]”uh1hµhj÷h²hh³hÊh´KÐjó}”j˜ j: sjõ}”jD j: subh¶)�”}”(hhh]”(h»)�”}”(hŒ SMT control”h]”hŒ SMT control”…”�”}”(hj  h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj� h²hh³hÊh´Kßubhû)�”}”(hXýAll MDS variants except MSBDS can be attacked cross Hyper-Threads. That means on CPUs which are affected by MFBDS or MLPDS it is necessary to disable SMT for full protection. These are most of the affected CPUs; the exception is XEON PHI, see :ref:`xeon_phi`. Disabling SMT can have a significant performance impact, but the impact depends on the type of workloads. See the relevant chapter in the L1TF mitigation documentation for details: :ref:`Documentation/admin-guide/hw-vuln/l1tf.rst `. ”h]”(hÌ)�”}”(hXAll MDS variants except MSBDS can be attacked cross Hyper-Threads. That means on CPUs which are affected by MFBDS or MLPDS it is necessary to disable SMT for full protection. These are most of the affected CPUs; the exception is XEON PHI, see :ref:`xeon_phi`.”h]”(hŒóAll MDS variants except MSBDS can be attacked cross Hyper-Threads. That means on CPUs which are affected by MFBDS or MLPDS it is necessary to disable SMT for full protection. These are most of the affected CPUs; the exception is XEON PHI, see ”…”�”}”(hj² h²hh³Nh´Nubh)�”}”(hŒ:ref:`xeon_phi`”h]”j‚)�”}”(hj¼ h]”hŒxeon_phi”…”�”}”(hj¾ h²hh³Nh´Nubah}”(h]”h ]”(j�Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hjº ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”jšŒ refdomain”jÈ Œreftype”Œref”Œ refexplicit”‰Œrefwarn”ˆj Œxeon_phi”uh1hh³hÊh´Káhj² ubhŒ.”…”�”}”(hj² h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Káhj® ubhÌ)�”}”(hŒiDisabling SMT can have a significant performance impact, but the impact depends on the type of workloads.”h]”hŒiDisabling SMT can have a significant performance impact, but the impact depends on the type of workloads.”…”�”}”(hjä h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kæhj® ubhÌ)�”}”(hŒ‹See the relevant chapter in the L1TF mitigation documentation for details: :ref:`Documentation/admin-guide/hw-vuln/l1tf.rst `.”h]”(hŒKSee the relevant chapter in the L1TF mitigation documentation for details: ”…”�”}”(hjò h²hh³Nh´Nubh)�”}”(hŒ?:ref:`Documentation/admin-guide/hw-vuln/l1tf.rst `”h]”j‚)�”}”(hjü h]”hŒ*Documentation/admin-guide/hw-vuln/l1tf.rst”…”�”}”(hjþ h²hh³Nh´Nubah}”(h]”h ]”(j�Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hjú ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”jšŒ refdomain”j Œreftype”Œref”Œ refexplicit”ˆŒrefwarn”ˆj Œ smt_control”uh1hh³hÊh´Kéhjò ubhŒ.”…”�”}”(hjò h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kéhj® ubeh}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´Káhj� h²hubj=)�”}”(hŒ(.. _mds_mitigation_control_command_line:”h]”h}”(h]”h ]”h"]”h$]”h&]”jHŒ#mds-mitigation-control-command-line”uh1j<h´Kíhj� h²hh³hÊubeh}”(h]”(Œ smt-control”j‘ eh ]”h"]”(Œ smt control”Œmds_smt_control”eh$]”h&]”uh1hµhj÷h²hh³hÊh´Kßjó}”j; j‡ sjõ}”j‘ j‡ subeh}”(h]”Œmitigation-mechanism”ah ]”h"]”Œmitigation mechanism”ah$]”h&]”uh1hµhh·h²hh³hÊh´K…ubh¶)�”}”(hhh]”(h»)�”}”(hŒ-Mitigation control on the kernel command line”h]”hŒ-Mitigation control on the kernel command line”…”�”}”(hjK h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjH h²hh³hÊh´KðubhÌ)�”}”(hŒ‹The kernel command line allows to control the MDS mitigations at boot time with the option "mds=". The valid arguments for this option are:”h]”hŒ�The kernel command line allows to control the MDS mitigations at boot time with the option “mds=â€�. The valid arguments for this option are:”…”�”}”(hjY h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KòhjH h²hubhû)�”}”(hX‡============ ============================================================= full If the CPU is vulnerable, enable all available mitigations for the MDS vulnerability, CPU buffer clearing on exit to userspace and when entering a VM. Idle transitions are protected as well if SMT is enabled. It does not automatically disable SMT. full,nosmt The same as mds=full, with SMT disabled on vulnerable CPUs. This is the complete mitigation. off Disables MDS mitigations completely. ============ ============================================================= ”h]”jæ)�”}”(hhh]”jë)�”}”(hhh]”(jð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”K uh1jïhjn ubjð)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œcolwidth”K=uh1jïhjn ubj)�”}”(hhh]”(j)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒfull”h]”hŒfull”…”�”}”(hjŽ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Köhj‹ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjˆ ubj)�”}”(hhh]”(hÌ)�”}”(hŒÐIf the CPU is vulnerable, enable all available mitigations for the MDS vulnerability, CPU buffer clearing on exit to userspace and when entering a VM. Idle transitions are protected as well if SMT is enabled.”h]”hŒÐIf the CPU is vulnerable, enable all available mitigations for the MDS vulnerability, CPU buffer clearing on exit to userspace and when entering a VM. Idle transitions are protected as well if SMT is enabled.”…”�”}”(hj¥ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Köhj¢ ubhÌ)�”}”(hŒ&It does not automatically disable SMT.”h]”hŒ&It does not automatically disable SMT.”…”�”}”(hj³ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kûhj¢ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjˆ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj… ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒ full,nosmt”h]”hŒ full,nosmt”…”�”}”(hjÓ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´KýhjÐ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÍ ubj)�”}”(hhh]”hÌ)�”}”(hŒ]The same as mds=full, with SMT disabled on vulnerable CPUs. This is the complete mitigation.”h]”hŒ]The same as mds=full, with SMT disabled on vulnerable CPUs. This is the complete mitigation.”…”�”}”(hjê h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Kýhjç ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÍ ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj… ubj)�”}”(hhh]”(j)�”}”(hhh]”hÌ)�”}”(hŒoff”h]”hŒoff”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Mhjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj)�”}”(hhh]”hÌ)�”}”(hŒ$Disables MDS mitigations completely.”h]”hŒ$Disables MDS mitigations completely.”…”�”}”(hj!h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Mhjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhj… ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jhjn ubeh}”(h]”h ]”h"]”h$]”h&]”Œcols”Kuh1jêhjk ubah}”(h]”h ]”h"]”h$]”h&]”uh1jåhjg ubah}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´KõhjH h²hubhÌ)�”}”(hXNot specifying this option is equivalent to "mds=full". For processors that are affected by both TAA (TSX Asynchronous Abort) and MDS, specifying just "mds=off" without an accompanying "tsx_async_abort=off" will have no effect as the same mitigation is used for both vulnerabilities.”h]”hX'Not specifying this option is equivalent to “mds=fullâ€�. For processors that are affected by both TAA (TSX Asynchronous Abort) and MDS, specifying just “mds=offâ€� without an accompanying “tsx_async_abort=offâ€� will have no effect as the same mitigation is used for both vulnerabilities.”…”�”}”(hjTh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´MhjH h²hubeh}”(h]”(Œ-mitigation-control-on-the-kernel-command-line”j4 eh ]”h"]”(Œ-mitigation control on the kernel command line”Œ#mds_mitigation_control_command_line”eh$]”h&]”uh1hµhh·h²hh³hÊh´Kðjó}”jhj* sjõ}”j4 j* subh¶)�”}”(hhh]”(h»)�”}”(hŒMitigation selection guide”h]”hŒMitigation selection guide”…”�”}”(hjph²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjmh²hh³hÊh´M ubh¶)�”}”(hhh]”(h»)�”}”(hŒ1. Trusted userspace”h]”hŒ1. Trusted userspace”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj~h²hh³hÊh´Mubhû)�”}”(hŒžIf all userspace applications are from a trusted source and do not execute untrusted code which is supplied externally, then the mitigation can be disabled. ”h]”hÌ)�”}”(hŒœIf all userspace applications are from a trusted source and do not execute untrusted code which is supplied externally, then the mitigation can be disabled.”h]”hŒœIf all userspace applications are from a trusted source and do not execute untrusted code which is supplied externally, then the mitigation can be disabled.”…”�”}”(hj“h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´Mhj�ubah}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´Mhj~h²hubeh}”(h]”Œtrusted-userspace”ah ]”h"]”Œ1. trusted userspace”ah$]”h&]”uh1hµhjmh²hh³hÊh´Mubh¶)�”}”(hhh]”(h»)�”}”(hŒ%2. Virtualization with trusted guests”h]”hŒ%2. Virtualization with trusted guests”…”�”}”(hj²h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhj¯h²hh³hÊh´Mubhû)�”}”(hŒBThe same considerations as above versus trusted user space apply. ”h]”hÌ)�”}”(hŒAThe same considerations as above versus trusted user space apply.”h]”hŒAThe same considerations as above versus trusted user space apply.”…”�”}”(hjÄh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´MhjÀubah}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´Mhj¯h²hubeh}”(h]”Œ"virtualization-with-trusted-guests”ah ]”h"]”Œ%2. virtualization with trusted guests”ah$]”h&]”uh1hµhjmh²hh³hÊh´Mubh¶)�”}”(hhh]”(h»)�”}”(hŒ'3. Virtualization with untrusted guests”h]”hŒ'3. Virtualization with untrusted guests”…”�”}”(hjãh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjàh²hh³hÊh´Mubhû)�”}”(hŒÇThe protection depends on the state of the L1TF mitigations. See :ref:`virt_mechanism`. If the MDS mitigation is enabled and SMT is disabled, guest to host and guest to guest attacks are prevented. ”h]”(hÌ)�”}”(hŒWThe protection depends on the state of the L1TF mitigations. See :ref:`virt_mechanism`.”h]”(hŒAThe protection depends on the state of the L1TF mitigations. See ”…”�”}”(hjõh²hh³Nh´Nubh)�”}”(hŒ:ref:`virt_mechanism`”h]”j‚)�”}”(hjÿh]”hŒvirt_mechanism”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”(j�Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hjýubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”jšŒ refdomain”j Œreftype”Œref”Œ refexplicit”‰Œrefwarn”ˆj Œvirt_mechanism”uh1hh³hÊh´MhjõubhŒ.”…”�”}”(hjõh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´MhjñubhÌ)�”}”(hŒmIf the MDS mitigation is enabled and SMT is disabled, guest to host and guest to guest attacks are prevented.”h]”hŒmIf the MDS mitigation is enabled and SMT is disabled, guest to host and guest to guest attacks are prevented.”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´M hjñubeh}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´Mhjàh²hubj=)�”}”(hŒ.. _mds_default_mitigations:”h]”h}”(h]”h ]”h"]”h$]”h&]”jHŒmds-default-mitigations”uh1j<h´M#hjàh²hh³hÊubeh}”(h]”Œ$virtualization-with-untrusted-guests”ah ]”h"]”Œ'3. virtualization with untrusted guests”ah$]”h&]”uh1hµhjmh²hh³hÊh´Mubeh}”(h]”Œmitigation-selection-guide”ah ]”h"]”Œmitigation selection guide”ah$]”h&]”uh1hµhh·h²hh³hÊh´M ubh¶)�”}”(hhh]”(h»)�”}”(hŒDefault mitigations”h]”hŒDefault mitigations”…”�”}”(hjYh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hºhjVh²hh³hÊh´M&ubhû)�”}”(hXPThe kernel default mitigations for vulnerable processors are: - Enable CPU buffer clearing The kernel does not by default enforce the disabling of SMT, which leaves SMT systems vulnerable when running untrusted code. The same rationale as for L1TF applies. See :ref:`Documentation/admin-guide/hw-vuln//l1tf.rst `.”h]”(hÌ)�”}”(hŒ=The kernel default mitigations for vulnerable processors are:”h]”hŒ=The kernel default mitigations for vulnerable processors are:”…”�”}”(hjkh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´M(hjgubj)�”}”(hhh]”j)�”}”(hŒEnable CPU buffer clearing ”h]”hÌ)�”}”(hŒEnable CPU buffer clearing”h]”hŒEnable CPU buffer clearing”…”�”}”(hj€h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´M*hj|ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjyubah}”(h]”h ]”h"]”h$]”h&]”jmjnuh1jh³hÊh´M*hjgubhÌ)�”}”(hŒóThe kernel does not by default enforce the disabling of SMT, which leaves SMT systems vulnerable when running untrusted code. The same rationale as for L1TF applies. See :ref:`Documentation/admin-guide/hw-vuln//l1tf.rst `.”h]”(hŒªThe kernel does not by default enforce the disabling of SMT, which leaves SMT systems vulnerable when running untrusted code. The same rationale as for L1TF applies. See ”…”�”}”(hjšh²hh³Nh´Nubh)�”}”(hŒH:ref:`Documentation/admin-guide/hw-vuln//l1tf.rst `”h]”j‚)�”}”(hj¤h]”hŒ+Documentation/admin-guide/hw-vuln//l1tf.rst”…”�”}”(hj¦h²hh³Nh´Nubah}”(h]”h ]”(j�Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j�hj¢ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”jšŒ refdomain”j°Œreftype”Œref”Œ refexplicit”ˆŒrefwarn”ˆj Œdefault_mitigations”uh1hh³hÊh´M,hjšubhŒ.”…”�”}”(hjšh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hËh³hÊh´M,hjgubeh}”(h]”h ]”h"]”h$]”h&]”uh1húh³hÊh´M(hjVh²hubeh}”(h]”(Œdefault-mitigations”jEeh ]”h"]”(Œdefault mitigations”Œmds_default_mitigations”eh$]”h&]”uh1hµhh·h²hh³hÊh´M&jó}”jØj;sjõ}”jEj;subeh}”(h]”Œ$mds-microarchitectural-data-sampling”ah ]”h"]”Œ&mds - microarchitectural data sampling”ah$]”h&]”uh1hµhhh²hh³hÊh´Kubeh}”(h]”h ]”h"]”h$]”h&]”Œsource”hÊuh1hŒcurrent_source”NŒ current_line”NŒsettings”Œdocutils.frontend”ŒValues”“”)�”}”(hºNŒ generator”NŒ datestamp”NŒ source_link”NŒ source_url”NŒ toc_backlinks”jŒfootnote_backlinks”KŒ sectnum_xform”KŒstrip_comments”NŒstrip_elements_with_classes”NŒ strip_classes”NŒ report_level”KŒ halt_level”KŒexit_status_level”KŒdebug”NŒwarning_stream”NŒ traceback”ˆŒinput_encoding”Œ utf-8-sig”Œinput_encoding_error_handler”Œstrict”Œoutput_encoding”Œutf-8”Œoutput_encoding_error_handler”jŒerror_encoding”Œutf-8”Œerror_encoding_error_handler”Œbackslashreplace”Œ language_code”Œen”Œrecord_dependencies”NŒconfig”NŒ id_prefix”hŒauto_id_prefix”Œid”Œ dump_settings”NŒdump_internals”NŒdump_transforms”NŒdump_pseudo_xml”NŒexpose_internals”NŒstrict_visitor”NŒ_disable_config”NŒ_source”hÊŒ _destination”NŒ _config_files”]”Œ7/var/lib/git/docbuild/linux/Documentation/docutils.conf”aŒfile_insertion_enabled”ˆŒ raw_enabled”KŒline_length_limit”M'Œpep_references”NŒ pep_base_url”Œhttps://peps.python.org/”Œpep_file_url_template”Œpep-%04d”Œrfc_references”NŒ rfc_base_url”Œ&https://datatracker.ietf.org/doc/html/”Œ tab_width”KŒtrim_footnote_reference_space”‰Œsyntax_highlight”Œlong”Œ smart_quotes”ˆŒsmartquotes_locales”]”Œcharacter_level_inline_markup”‰Œdoctitle_xform”‰Œ docinfo_xform”KŒsectsubtitle_xform”‰Œ image_loading”Œlink”Œembed_stylesheet”‰Œcloak_email_addresses”ˆŒsection_self_link”‰Œenv”NubŒreporter”NŒindirect_targets”]”Œsubstitution_defs”}”Œsubstitution_names”}”Œrefnames”}”Œrefids”}”(jI]”j>ajR]”jHaj¢]”j˜ajD ]”j: aj‘ ]”j‡ aj4 ]”j* ajE]”j;auŒnameids”}”(jâjßj¿j¼jnjkjãjàjWjTjOjLjðjIjïjìjE jB j©jRj¨j¥jK j¢jJ jG j˜ jD j— j” j; j‘ j: j7 jhj4 jgjdjSjPj¬j©jÝjÚjKjHjØjEj×jÔuŒ nametypes”}”(jâ‰j¿‰jn‰jã‰jW‰jO‰jðˆjï‰jE ‰j©ˆj¨‰jK ˆjJ ‰j˜ ˆj— ‰j; ˆj: ‰jhˆjg‰jS‰j¬‰j݉jK‰j؈j׉uh}”(jßh·j¼hÛjkjÂjàjqjTjæjLjjIjZjìjZjB j÷jRjSj¥jSj¢j®jG j®jD jP j” jP j‘ j� j7 j� j4 jH jdjH jPjmj©j~jÚj¯jHjàjEjVjÔjVuŒ footnote_refs”}”Œ citation_refs”}”Œ autofootnotes”]”Œautofootnote_refs”]”Œsymbol_footnotes”]”Œsymbol_footnote_refs”]”Œ footnotes”]”Œ citations”]”Œautofootnote_start”KŒsymbol_footnote_start”KŒ id_counter”Œ collections”ŒCounter”“”}”…”R”Œparse_messages”]”Œtransform_messages”]”(hŒsystem_message”“”)�”}”(hhh]”hÌ)�”}”(hhh]”hŒ2Hyperlink target "mds-sys-info" is not referenced.”…”�”}”hjwsbah}”(h]”h ]”h"]”h$]”h&]”uh1hËhjtubah}”(h]”h ]”h"]”h$]”h&]”Œlevel”KŒtype”ŒINFO”Œsource”hÊŒline”KUuh1jrubjs)�”}”(hhh]”hÌ)�”}”(hhh]”hŒ6Hyperlink target "cpu-buffer-clear" is not referenced.”…”�”}”hj’sbah}”(h]”h ]”h"]”h$]”h&]”uh1hËhj�ubah}”(h]”h ]”h"]”h$]”h&]”Œlevel”KŒtype”jŒŒsource”hÊŒline”K�uh1jrubjs)�”}”(hhh]”hÌ)�”}”(hhh]”hŒ4Hyperlink target "virt-mechanism" is not referenced.”…”�”}”hj¬sbah}”(h]”h ]”h"]”h$]”h&]”uh1hËhj©ubah}”(h]”h ]”h"]”h$]”h&]”Œlevel”KŒtype”jŒŒsource”hÊŒline”Kžuh1jrubjs)�”}”(hhh]”hÌ)�”}”(hhh]”hŒ.Hyperlink target "xeon-phi" is not referenced.”…”�”}”hjÆsbah}”(h]”h ]”h"]”h$]”h&]”uh1hËhjÃubah}”(h]”h ]”h"]”h$]”h&]”Œlevel”KŒtype”jŒŒsource”hÊŒline”KÍuh1jrubjs)�”}”(hhh]”hÌ)�”}”(hhh]”hŒ5Hyperlink target "mds-smt-control" is not referenced.”…”�”}”hjàsbah}”(h]”h ]”h"]”h$]”h&]”uh1hËhjÝubah}”(h]”h ]”h"]”h$]”h&]”Œlevel”KŒtype”jŒŒsource”hÊŒline”KÜuh1jrubjs)�”}”(hhh]”hÌ)�”}”(hhh]”hŒIHyperlink target "mds-mitigation-control-command-line" is not referenced.”…”�”}”hjúsbah}”(h]”h ]”h"]”h$]”h&]”uh1hËhj÷ubah}”(h]”h ]”h"]”h$]”h&]”Œlevel”KŒtype”jŒŒsource”hÊŒline”Kíuh1jrubjs)�”}”(hhh]”hÌ)�”}”(hhh]”hŒ=Hyperlink target "mds-default-mitigations" is not referenced.”…”�”}”hjsbah}”(h]”h ]”h"]”h$]”h&]”uh1hËhjubah}”(h]”h ]”h"]”h$]”h&]”Œlevel”KŒtype”jŒŒsource”hÊŒline”M#uh1jrubeŒ transformer”NŒ include_log”]”Œ decoration”Nh²hub.