By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Linux 6.17-rc2 To Better Tune Attack Vector Controls For SRSO Mitigation
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Linux 6.17-rc2 To Better Tune Attack Vector Controls For SRSO Mitigation
Computing

Linux 6.17-rc2 To Better Tune Attack Vector Controls For SRSO Mitigation

News Room
Last updated: 2025/08/17 at 9:53 AM
News Room Published 17 August 2025
Share
SHARE

One of the new exciting security features with Linux 6.17 is Attack Vector Controls as a means of easier managing CPU security mitigations depending upon the system/server use-case. It drastically simplifies CPU security mitigation management for only activating the mitigations relevant to intended use. With the Linux 6.17-rc2 kernel due out later today, Attack Vector Controls refines its logic around the Speculative Return Stack Overflow (SRSO) mitigation.

Sent out today were the x86 fixes ahead of Linux 6.17-rc2 coming out later today. With this week’s x86/urgent pull request is adjusting the SRSO mitigation behavior for Attack Vector Controls. AMD engineer David Kaplan who spearheaded the Attack Vector Controls effort explains with the patch refinement:

“The SRSO bug can theoretically be used to conduct user->user or guest->guest attacks and requires a mitigation (namely IBPB instead of SBPB on context switch) for these. So mark SRSO as being applicable to the user->user and guest->guest attack vectors.

Additionally, SRSO supports multiple mitigations which mitigate different potential attack vectors. Some CPUs are also immune to SRSO from certain attack vectors (like user->kernel).

Use the specific attack vectors requiring mitigation to select the best SRSO mitigation to avoid unnecessary performance hits.”

That’s in this pull along with separately better ensuring AMD SEV guest driver buffers used in encryption operations are linear mapped to help in possible encryption offloading. Plus a few other fixes:

– Remove a transitional asm/cpuid.h header which was added only as a fallback during cpuid helpers reorg

– Initialize reserved fields in the SVSM page validation calls structure to zero in order to allow for future structure extensions

– Have the sev-guest driver’s buffers used in encryption operations be in linear mapping space as the encryption operation can be offloaded to an accelerator

– Have a read-only MSR write when in an AMD SNP guest trap to the hypervisor as it is usually done. This makes the guest user experience better by simply raising a #GP instead of terminating said guest

– Do not output AVX512 elapsed time for kernel threads because the data is wrong and fix a NULL pointer dereferencing in the process

– Adjust the SRSO mitigation selection to the new attack vectors

Linux 6.17 with its many new features should be out as stable by early October.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Mom traveling with baby hit with $3.6k ‘seating’ fee from American Airlines
Next Article The one feature that keeps me from recommending flip phones
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

5 reasons why I use separate speakers for my TV and music
News
How to Manage Instagram DMs
Computing
Ben Stiller, Tramell Tillman bring a 'Severance' marching band to a 'Zoolander' screening
News
The Galaxy S26 Pro might kill the best Samsung phone for most people
News

You Might also Like

Computing

How to Manage Instagram DMs

14 Min Read
Computing

How to Use a Color-Coded Calendar to Organize Your Schedule

19 Min Read
Computing

Beyond Anti-Patterns: How Skilled Pairs Stay on Track | HackerNoon

5 Min Read
Computing

Chinese EVs’ share of global market rose in 2023: industry group · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?