Comment 2 for bug 1891812

Revision history for this message
Thadeu Lima de Souza Cascardo (cascardo) wrote :

https://aws.amazon.com/security/security-bulletins/AWS-2019-004/

According to Amazon advisory, fixes have been applied and "no customer action is required at the Infrastructure level". Reading from other sources [1], I can only conclude that Amazon has not provided the knobs needed to do the mitigation. This explains the issue for MDS and TAA. SSB is likely vulnerable for the same reasons, but I'll look for their advisory and update it here. Same thing for ITLB multihit.

One possible avenue of investigation is verifying if VERW is being used and providing the mitigation for the MDS case.

Regards.
Cascardo.

[1] https://www.reddit.com/r/aws/comments/br38fl/sidechannel_md_clear_cpu_flags_not_being_passed/