From: Paul Barker <paul@pbarker.dev>
To: Junjie Cao <junjie.cao@linux.dev>,
openembedded-core@lists.openembedded.org
Subject: Re: [OE-core][PATCH v3 2/9] cve-exclusions: set status for CVE-2021-3714
Date: Sun, 16 Aug 2026 16:53:27 +0100 [thread overview]
Message-ID: <79c7d5ad090b78b3d867ac3637cd6da41b518c2c.camel@pbarker.dev> (raw)
In-Reply-To: <20260812072842.1176341-3-junjie.cao@linux.dev>
On Wed, 2026-08-12 at 02:28 -0500, Junjie Cao wrote:
> KSM merges identical anonymous pages across processes. An attacker who
> can place chosen page-sized content in a victim's memory can detect the
> merge through the timing of the resulting copy-on-write fault, and so
> leak memory contents.
>
> There is no upstream fix; removing the side channel means removing
> deduplication. Distribution trackers describe it the same way - Debian
> marks src:linux unfixed with "Inherent design limitation, can be avoided
> by not using KSM", Red Hat closed its bug WONTFIX, and Ubuntu records no
> upstream fix as of 2024-06-17:
>
> https://security-tracker.debian.org/tracker/CVE-2021-3714
> https://bugzilla.redhat.com/show_bug.cgi?id=1931327
> https://ubuntu.com/security/CVE-2021-3714
>
> Exposure requires two runtime opt-ins: ksmd must be started by the
> administrator (ksm_run defaults to KSM_RUN_STOP in mm/ksm.c) and memory
> is only eligible when a process asks with madvise(MADV_MERGEABLE) or
> prctl(PR_SET_MEMORY_MERGE). CONFIG_KSM=y is set in yocto-kernel-cache
> (bsp/intel-x86 and the paravirt_kvm fragments), so this is not a
> configuration exclusion.
We should drop this third paragraph - it's time consuming to validate.
>
> CC: Paul Barker <paul@pbarker.dev>
> AI-Generated: Uses Claude (claude-opus-5)
> Signed-off-by: Junjie Cao <junjie.cao@linux.dev>
> ---
> v3:
> - use "unpatched" instead of "upstream-wontfix": the WONTFIX is a
> distribution position, not an upstream one
>
> v2: https://lore.kernel.org/openembedded-core/20260803084827.1348810-1-junjie.cao@linux.dev/
>
> meta/recipes-kernel/linux/cve-exclusion.inc | 7 +++++++
> 1 file changed, 7 insertions(+)
>
> diff --git a/meta/recipes-kernel/linux/cve-exclusion.inc b/meta/recipes-kernel/linux/cve-exclusion.inc
> index 5ed4a00..af3576d 100644
> --- a/meta/recipes-kernel/linux/cve-exclusion.inc
> +++ b/meta/recipes-kernel/linux/cve-exclusion.inc
> @@ -199,3 +199,10 @@ CVE_STATUS[CVE-2025-71145] = "cpe-stable-backport: Fixed from v6.18.3"
> # https://ubuntu.com/security/CVE-2019-14899
> CVE_STATUS[CVE-2019-14899] = "unpatched: consequence of the default weak \
> host model, no upstream kernel fix, mitigated by firewall configuration"
> +
> +# Timing side channel inherent to KSM page deduplication. Reachable only
> +# when ksmd is started (/sys/kernel/mm/ksm/run defaults to 0) and the
> +# workload opts in via MADV_MERGEABLE or prctl(PR_SET_MEMORY_MERGE).
> +# https://security-tracker.debian.org/tracker/CVE-2021-3714
> +CVE_STATUS[CVE-2021-3714] = "unpatched: timing side channel inherent to \
> +KSM page deduplication, only reachable when KSM is enabled and opted into"
I recommend we change the wording, add more links and include the triage
date:
# Triaged August 2026 - no upstream fix, Debian says "Inherent design
# limitation, can be avoided by not using KSM", Red Hat closed their bug as
# WONTFIX.
# https://security-tracker.debian.org/tracker/CVE-2021-3714
# https://bugzilla.redhat.com/show_bug.cgi?id=1931327
# https://ubuntu.com/security/CVE-2021-3714
CVE_STATUS[CVE-2021-3714] = "unpatched: Timing side channel inherent to Kernel \
Same-page Merging (KSM) page deduplication"
Best regards,
--
Paul Barker
next prev parent reply other threads:[~2026-08-16 15:53 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 7:28 [OE-core][PATCH v3 0/9] cve-exclusions: triage nine kernel CVEs lacking upstream fix data Junjie Cao
2026-08-12 7:28 ` [OE-core][PATCH v3 1/9] cve-exclusions: set status for CVE-2019-14899 Junjie Cao
2026-08-16 15:50 ` Paul Barker
2026-08-12 7:28 ` [OE-core][PATCH v3 2/9] cve-exclusions: set status for CVE-2021-3714 Junjie Cao
2026-08-16 15:53 ` Paul Barker [this message]
2026-08-12 7:28 ` [OE-core][PATCH v3 3/9] cve-exclusions: set status for CVE-2021-3864 Junjie Cao
2026-08-16 15:55 ` Paul Barker
2026-08-12 7:28 ` [OE-core][PATCH v3 4/9] cve-exclusions: set status for CVE-2022-0400 Junjie Cao
2026-08-16 16:35 ` Paul Barker
2026-08-12 7:28 ` [OE-core][PATCH v3 5/9] cve-exclusions: set status for CVE-2022-1247 Junjie Cao
2026-08-16 16:21 ` Paul Barker
2026-08-12 7:28 ` [OE-core][PATCH v3 6/9] cve-exclusions: set status for CVE-2022-4543 Junjie Cao
2026-08-16 16:00 ` Paul Barker
2026-08-12 7:28 ` [OE-core][PATCH v3 7/9] cve-exclusions: set status for CVE-2023-3397 Junjie Cao
2026-08-16 16:05 ` Paul Barker
2026-08-12 7:28 ` [OE-core][PATCH v3 8/9] cve-exclusions: set status for CVE-2023-6238 Junjie Cao
2026-08-16 16:11 ` Paul Barker
2026-08-12 7:28 ` [OE-core][PATCH v3 9/9] cve-exclusions: set status for CVE-2023-6240 Junjie Cao
2026-08-16 16:14 ` Paul Barker
2026-08-16 16:39 ` [OE-core][PATCH v3 0/9] cve-exclusions: triage nine kernel CVEs lacking upstream fix data Paul Barker
2026-08-19 10:43 ` Junjie Cao
2026-08-24 4:13 ` Junjie Cao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=79c7d5ad090b78b3d867ac3637cd6da41b518c2c.camel@pbarker.dev \
--to=paul@pbarker.dev \
--cc=junjie.cao@linux.dev \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.