By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Linux 6.17-rc2 To Better Tune Attack Vector Controls For SRSO Mitigation
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Linux 6.17-rc2 To Better Tune Attack Vector Controls For SRSO Mitigation
Computing

Linux 6.17-rc2 To Better Tune Attack Vector Controls For SRSO Mitigation

News Room
Last updated: 2025/08/17 at 9:53 AM
News Room Published 17 August 2025
Share
SHARE

One of the new exciting security features with Linux 6.17 is Attack Vector Controls as a means of easier managing CPU security mitigations depending upon the system/server use-case. It drastically simplifies CPU security mitigation management for only activating the mitigations relevant to intended use. With the Linux 6.17-rc2 kernel due out later today, Attack Vector Controls refines its logic around the Speculative Return Stack Overflow (SRSO) mitigation.

Sent out today were the x86 fixes ahead of Linux 6.17-rc2 coming out later today. With this week’s x86/urgent pull request is adjusting the SRSO mitigation behavior for Attack Vector Controls. AMD engineer David Kaplan who spearheaded the Attack Vector Controls effort explains with the patch refinement:

“The SRSO bug can theoretically be used to conduct user->user or guest->guest attacks and requires a mitigation (namely IBPB instead of SBPB on context switch) for these. So mark SRSO as being applicable to the user->user and guest->guest attack vectors.

Additionally, SRSO supports multiple mitigations which mitigate different potential attack vectors. Some CPUs are also immune to SRSO from certain attack vectors (like user->kernel).

Use the specific attack vectors requiring mitigation to select the best SRSO mitigation to avoid unnecessary performance hits.”

That’s in this pull along with separately better ensuring AMD SEV guest driver buffers used in encryption operations are linear mapped to help in possible encryption offloading. Plus a few other fixes:

– Remove a transitional asm/cpuid.h header which was added only as a fallback during cpuid helpers reorg

– Initialize reserved fields in the SVSM page validation calls structure to zero in order to allow for future structure extensions

– Have the sev-guest driver’s buffers used in encryption operations be in linear mapping space as the encryption operation can be offloaded to an accelerator

– Have a read-only MSR write when in an AMD SNP guest trap to the hypervisor as it is usually done. This makes the guest user experience better by simply raising a #GP instead of terminating said guest

– Do not output AVX512 elapsed time for kernel threads because the data is wrong and fix a NULL pointer dereferencing in the process

– Adjust the SRSO mitigation selection to the new attack vectors

Linux 6.17 with its many new features should be out as stable by early October.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Mom traveling with baby hit with $3.6k ‘seating’ fee from American Airlines
Next Article The one feature that keeps me from recommending flip phones
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The best iPad for reading and traveling is $100 off
News
Huawei regains the top spot in Chinese smartphone sales in the first two weeks of 2024 · TechNode
Computing
Why Your AirPods Keep Pausing And How To Fix It – BGR
News
Nvidia releases massive AI-ready European language dataset and tools – News
News

You Might also Like

Computing

Huawei regains the top spot in Chinese smartphone sales in the first two weeks of 2024 · TechNode

1 Min Read
Computing

Instagram Tips for Creatives: Optimizing Your Instagram Portfolio

13 Min Read
Computing

Week in Review: Most popular stories on GeekWire for the week of Aug. 10, 2025

4 Min Read
Computing

GM, Toyota, BYD-backed Chinese self-driving startup seeks US listing: report · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?