Re: [qubes-users] QSB #058: Insufficient cache write-back under VT-d (XSA-321)

2020-07-08 Thread haaber

On 7/8/20 5:58 PM, taran1s wrote:



Chris Laprise:

On 7/7/20 9:57 AM, Andrew David Wong wrote:

Only Intel systems are affected. AMD systems are not affected.


Per usual!



Is actually the XSA-321 a security issue only if one has HVM present in
the Qubes system, or it is a general issue even if there is no HVM?

Are there any security advices or a good practice to follow before the
patch is available?


I am not an expert on this, but I believe for sys-usb and sys-net you
have no real choice in most of the systems: PCI passthrough requires "no
PVH".

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/0d60972a-695b-b04e-caed-bec10e5e1bd2%40web.de.


Re: [qubes-users] QSB #058: Insufficient cache write-back under VT-d (XSA-321)

2020-07-08 Thread taran1s


Chris Laprise:
> On 7/7/20 9:57 AM, Andrew David Wong wrote:
>> Only Intel systems are affected. AMD systems are not affected.
> 
> Per usual!
> 

Is actually the XSA-321 a security issue only if one has HVM present in
the Qubes system, or it is a general issue even if there is no HVM?

Are there any security advices or a good practice to follow before the
patch is available?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/4fff9f92-71d1-9d3f-7a6e-646427f0a955%40mailbox.org.


0xA664B90BD3BE59B3.asc
Description: application/pgp-keys


Re: [qubes-users] QSB #058: Insufficient cache write-back under VT-d (XSA-321)

2020-07-07 Thread Chris Laprise

On 7/7/20 9:57 AM, Andrew David Wong wrote:

Only Intel systems are affected. AMD systems are not affected.


Per usual!

--
Chris Laprise, tas...@posteo.net
https://github.com/tasket
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB  4AB3 1DC4 D106 F07F 1886

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/6470bedd-0536-be4e-32f6-2ca7ee1fd1c6%40posteo.net.