MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
devices
Search

[$] Bounce buffers for untrusted devices

Friday April 26, 2019. 05:26 PM , from LWN.net
The recently discovered vulnerability in
Thunderbolt has restarted discussions about protecting the kernel
against untrusted, hotpluggable hardware. That vulnerability, known as Thunderclap, allows a hostile external
device to exploit Input-Output
Memory Management Unit (IOMMU) mapping limitations and access system
memory it was not intended to. Thunderclap can be exploited by
USB-C-connected devices; while we have seen USB attacks in the past, this
vulnerability is different in that PCI devices, often considered as
trusted, can be a source of attacks too. One way of stopping those attacks
would be to make sure that the IOMMU is used correctly and restricts the device
to accessing the memory that was allocated for it. Lu Baolu has posted
an implementation of that approach in the form of bounce buffers for
untrusted devices.
https://lwn.net/Articles/786558/rss
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
Apr, Thu 25 - 23:08 CEST