fix: xen: consider Xen dom0 as non-guest (#343 continued)

(cherry picked from commit bc00a81526)
This commit is contained in:
Stéphane Lesimple
2026-08-08 17:23:47 +00:00
parent cc29aaba6b
commit d5cbaaa7c3
5 changed files with 62 additions and 17 deletions
+12 -4
View File
@@ -87,10 +87,18 @@ check_CVE_2019_11135_linux() {
elif echo "$ret_sys_interface_check_fullmsg" | grep -qF 'SMT vulnerable'; then
pvulnstatus "$cve" VULN "SMT (HyperThreading) must be disabled for full mitigation"
elif echo "$ret_sys_interface_check_fullmsg" | grep -qF 'SMT Host state unknown'; then
# The kernel appends "SMT Host state unknown" when running under a
# hypervisor (X86_FEATURE_HYPERVISOR): the host controls SMT
# scheduling, so it can't be determined from inside the guest (#343).
pvulnstatus "$cve" UNK "TAA is mitigated and TSX is disabled, but SMT (Hyper-Threading) cross-thread protection can't be verified from inside a VM guest: it depends on the hypervisor host's SMT/core-scheduling configuration"
# "SMT Host state unknown" is emitted whenever the HYPERVISOR
# CPUID bit is set -- true both inside a guest AND on a Xen dom0
# (#343). In a guest we can't see the host's SMT scheduling; on
# dom0/bare metal the local SMT state is authoritative, so trust
# it there.
if is_running_as_guest; then
pvulnstatus "$cve" UNK "TAA is mitigated and TSX is disabled, but SMT (Hyper-Threading) cross-thread protection can't be verified from inside a VM guest: it depends on the hypervisor host's SMT/core-scheduling configuration"
elif is_cpu_smt_enabled; then
pvulnstatus "$cve" VULN "SMT (HyperThreading) must be disabled for full mitigation"
else
pvulnstatus "$cve" "$status" "$msg"
fi
else
pvulnstatus "$cve" "$status" "$msg"
fi