From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A99A7168DC for ; Sun, 19 May 2024 08:35:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716107731; cv=none; b=ukVZUtC2QiX8vGpIgkWzhqiyZ7lwmZUJ89ZbCGqrsuStUmj469uJnIAM5G1hJJP87YrqYNR2QjE4Ifs3IKDefN5oVLiDLtIFkXM5qyaPB2/GJg5VDKghAKQfY+2WJby9XkT+M028klWCJySBzrw7u6v9G8iCgB+IwR283D0Bb1Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716107731; c=relaxed/simple; bh=lDah2AIyZbJNhMfKkca326ZQ66WbDobe1Q0brznFsVg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=VBwebHmc+3T7qrodejt8svkk+JzzjQtW938e33a73cguJ3z0OfIvO7b1lNy4YmnMDW1zwPMwxUgfomLjbb+CyK3tx9rcGZgqmlZkl+wzQ9/u3ZYBTGS8ge+jmqcStiI6XnMqgoPQ+fni+RAwD+x8ztnfOEYWWci4QnQ46u6Nkgw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=YYGJ02H1; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="YYGJ02H1" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C5E94C32781; Sun, 19 May 2024 08:35:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1716107731; bh=lDah2AIyZbJNhMfKkca326ZQ66WbDobe1Q0brznFsVg=; h=From:To:Cc:Subject:Date:Reply-to:From; b=YYGJ02H12bnED3lARyWrTyvDiiI5ksjlt3LDgcqCCcbxBckypzrPX7UPu0SQSNO5J OXOcwXQaL0rjDZIl2i1dlpqSWaNnLo6Fs++MOCQ5Qh84Twf0/P+ziPdWyhJHABh37t KgantP1wablqT/0O3exZoB4FgI0FCAclO/7SJTv0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2024-35875: x86/coco: Require seeding RNG with RDRAND on CoCo systems Date: Sun, 19 May 2024 10:34:49 +0200 Message-ID: <2024051942-CVE-2024-35875-e23d@gregkh> X-Mailer: git-send-email 2.45.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=3475; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=lDah2AIyZbJNhMfKkca326ZQ66WbDobe1Q0brznFsVg=; b=owGbwMvMwCRo6H6F97bub03G02pJDGmeOxdpXe8L2z/DeNLmsGUzZTUObl/64IPc4c1vX6p5/ FQumJJwoyOWhUGQiUFWTJHlyzaeo/srDil6GdqehpnDygQyhIGLUwAmsrSMYcF8L4OvGhX/hW5H +q/yToioCOlWV2CYX71YbM+2GXqOElJx6fIHf5nvepiyAAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: x86/coco: Require seeding RNG with RDRAND on CoCo systems There are few uses of CoCo that don't rely on working cryptography and hence a working RNG. Unfortunately, the CoCo threat model means that the VM host cannot be trusted and may actively work against guests to extract secrets or manipulate computation. Since a malicious host can modify or observe nearly all inputs to guests, the only remaining source of entropy for CoCo guests is RDRAND. If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole is meant to gracefully continue on gathering entropy from other sources, but since there aren't other sources on CoCo, this is catastrophic. This is mostly a concern at boot time when initially seeding the RNG, as after that the consequences of a broken RDRAND are much more theoretical. So, try at boot to seed the RNG using 256 bits of RDRAND output. If this fails, panic(). This will also trigger if the system is booted without RDRAND, as RDRAND is essential for a safe CoCo boot. Add this deliberately to be "just a CoCo x86 driver feature" and not part of the RNG itself. Many device drivers and platforms have some desire to contribute something to the RNG, and add_device_randomness() is specifically meant for this purpose. Any driver can call it with seed data of any quality, or even garbage quality, and it can only possibly make the quality of the RNG better or have no effect, but can never make it worse. Rather than trying to build something into the core of the RNG, consider the particular CoCo issue just a CoCo issue, and therefore separate it all out into driver (well, arch/platform) code. [ bp: Massage commit message. ] The Linux kernel CVE team has assigned CVE-2024-35875 to this issue. Affected and fixed versions =========================== Fixed in 6.1.85 with commit 22943e4fe4b3 Fixed in 6.6.26 with commit 453b5f2dec27 Fixed in 6.8.5 with commit 08044b08b375 Fixed in 6.9 with commit 99485c4c026f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2024-35875 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: arch/x86/coco/core.c arch/x86/include/asm/coco.h arch/x86/kernel/setup.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/22943e4fe4b3a2dcbadc3d38d5bf840bbdbfe374 https://git.kernel.org/stable/c/453b5f2dec276c1bb4ea078bf8c0da57ee4627e5 https://git.kernel.org/stable/c/08044b08b37528b82f70a87576c692b4e4b7716e https://git.kernel.org/stable/c/99485c4c026f024e7cb82da84c7951dbe3deb584