Bug 1217857 (CVE-2024-2193) - VUL-0: CVE-2024-2193: GhostRace: Exploiting and Mitigating Speculative Race Conditions
Summary: VUL-0: CVE-2024-2193: GhostRace: Exploiting and Mitigating Speculative Race C...
Status: RESOLVED WONTFIX
Alias: CVE-2024-2193
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Nikolay Borisov
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/387230/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-2193:5.5:(AV:L...
Keywords:
Depends on:
Blocks: 1221334
  Show dependency treegraph
 
Reported: 2023-12-06 16:09 UTC by Marcus Meissner
Modified: 2024-05-27 14:45 UTC (History)
5 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 4 Marcus Meissner 2024-02-07 16:55:26 UTC
CRD: 2024-03-03
Comment 5 Marcus Meissner 2024-02-13 14:07:16 UTC
new
CRD: 2024-03-12
Comment 6 Marcus Meissner 2024-02-27 09:14:25 UTC
https://bugzilla.suse.com/show_bug.cgi?id=1220398  related public CVE bug for sys_membarrier  (that was used to slow down the system)
Comment 7 Nikolay Borisov 2024-03-05 09:14:43 UTC
AFAIU there won't be any specific fixes being released for this one? The sys_membarrier one should have already been fixed by jiri slaby?
Comment 8 Marcus Meissner 2024-03-13 07:37:41 UTC
my understanding is that the paper recommends an lfence after the locking primitives?
Comment 9 Nikolay Borisov 2024-03-13 08:44:33 UTC
(In reply to Marcus Meissner from comment #8)
> my understanding is that the paper recommends an lfence after the locking
> primitives?

Yes, however: 


AMD recommends simply following best practices for Spectre v1: 
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7016.html

As per researcher's own disclosure page: 

> The Linux kernel developers have no immediate plans to implement our proposed 
> serialization of synchronization primitives due to performance concerns. 


So I'd say we should close this issue as won't fix/invalid.
Comment 10 Nikolay Borisov 2024-03-18 12:30:55 UTC
How do we proceed with this one ?
Comment 11 Marcus Meissner 2024-03-18 14:01:02 UTC
https://www.vusec.net/projects/ghostrace/

To be very frank, I would like to have the lfence mitigation for the spinlocks.

Should we discuss this with SUSE kernel team?
Comment 12 Nikolay Borisov 2024-03-18 14:50:19 UTC
(In reply to Marcus Meissner from comment #11)
> https://www.vusec.net/projects/ghostrace/
> 
> To be very frank, I would like to have the lfence mitigation for the
> spinlocks.
> 
> Should we discuss this with SUSE kernel team?

Yes discuss it and I will vehemently oppose it.
Comment 14 Nikolay Borisov 2024-03-21 14:48:24 UTC
I cosnide the topic closed. Shall we closed as resolved/invalid/won't  fix already ?
Comment 15 Nikolay Borisov 2024-05-27 11:31:34 UTC
Shall we get this closed once and for all ?
Comment 16 Marcus Meissner 2024-05-27 14:45:46 UTC
currently we are not planning to put in additional fixes for this issue.