A security oversight in the Linux kernel has left legacy I/O and memory sysfs interfaces (legacy_io and legacy_mem) unprotected in kernel lockdown mode since 2019. Even with lockdown enabled — typically activated alongside UEFI Secure Boot — root users could still write to arbitrary I/O ports and map legacy PCI memory space, bypassing the very protections lockdown is meant to enforce. A patch by Krzysztof Wilczyński has been queued into the PCI subsystem's 'next' branch targeting Linux 7.3, and is expected to be backported to stable kernel versions.
20 Impressions