A security oversight in the Linux kernel has left legacy I/O and memory sysfs interfaces (legacy_io and legacy_mem) unprotected in kernel lockdown mode since 2019. Even with lockdown enabled — typically activated alongside UEFI Secure Boot — root users could still write to arbitrary I/O ports and map legacy PCI memory space, bypassing the very protections lockdown is meant to enforce. A patch by Krzysztof Wilczyński has been queued into the PCI subsystem's 'next' branch targeting Linux 7.3, and is expected to be backported to stable kernel versions.

2m read timeFrom phoronix.com
Post cover image
82 Impressions