Stéphane Lesimple
60ea669e41
enh: better explain the 4 run modes
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
f1c0d5548c
chg: remove --no-intel-db, it's now always used when available
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
9e617a4363
remove prometheus-legacy format
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
b9c203120b
enh: --no-runtime and --no-hw modes replacing --live and implicit 'offline' mode
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
3f7e0a11f7
enh: CVE-2018-3640 (Spectre 3a): enhance ARM mitigation detection
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
5c469787ea
enh: rework --batch nrpe entirely
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
a952fe32c4
fix: exit_cleanup: don't lose passed exit code
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
61fa02d577
feat: rework the --batch prometheus output entirely
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
39dea1245e
feat: rework the --batch json output entirely
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
3afbda8430
enh: when reading CPUID is unavailable (VM?), fallback to cpuinfo where applicable
...
cap_* variable <= cpuinfo flag
cap_ibrs <= ibrs
cap_ibpb <= ibpb
cap_stibp <= stibp
cap_ssbd <= ssbd / virt_ssbd
cap_l1df <= flush_l1d
cap_md_clear <= md_clear
cap_arch_capabilities <= arch_capabilities
Should fix #288
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
6d69ce9a77
enh: read/write_msr: clearer error messages
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
3ebfba2ac2
fix: CVE-2017-5715 (Spectre V2): Red Hat specific fix for RSB Filling ( fixes #235 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
a3f6553e65
fix: read/write msr and lockdown: fix a variable error, properly report lockdown to users
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
42ed8efa65
fix: better compatibility under busybox, silence buggy unzlma versions ( fix #432 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
2c766b7cc6
fix: wrmsr: specify core number ( closes #294 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
49472f1b64
enh: clearer kernel info section at the top of the script
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
333aa74fea
enh: clearer CPU details section
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
8d9504d174
chore: add comment about is_intel/amd/hygon recursion
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
6043f586ef
enh: update IntelDB affected CPU list to 2026-04 data, including Hybrid CPU detection
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
e1ace7c281
doc: document Platypus (CVE-2020-8694 CVE-2020-8695) as out of scope ( #384 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
24ab98d757
doc: document CVE-2020-24511 and CVE-2020-24512 as being out of scope along with rationale ( #409 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
155b3808b9
fix: CPUs affected by MSBDS but not MDS ( fix #351 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
b6a41918b0
doc: add CVE-2019-11157 (Plundervolt) to unsupported CVE list
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
3c56ac35dd
fix: better detect kernel lockdown & no longer require cap_flush_cmd to deem CVE-2018-3615 as mitigated ( fix #296 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
b0bb1f4676
feat: implement check for MMIO Stale Data (CVE-2022-21123 CVE-2022-21125 CVE-2022-21166) ( #437 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
0fa7e44327
doc: add Blindside to unsupported list ( #374 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
f100b4e1dc
doc: add CVE-2020-0549 (L1D Eviction Sampling, CacheOut) as unsupported
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
6332fc3405
fix: CVE-2019-11135 (TAA) detect new 0x10F MSR for TSX-disabled CPUs ( #414 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
3c61c7489b
fix: CVE-2024-3635[0,7] don't print lines about TSA CPUID bits under non-AMD
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
3d01978cd4
feat: add CVE-2023-20588 (AMD DIV0 bug) ( #473 )
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
53c45e3363
doc: update dev guidelines
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
acf8b585a5
doc: add CVE-2024-2201 (Native BHI) and TLBleed as unsupported
2026-04-08 22:35:53 +02:00
Stéphane Lesimple
076a1d5723
fix: CVE-2020-0543 (SRBDS): microcode mitigation misdetected ( #492 )
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
ee618ead07
enh: detect IPBP return predictor bypass in Inception/SRSO ("PB-Inception") ( #500 )
...
AMD Zen 1-3 CPUs don't flush return predictions on IBPB, allowing
cross-process Spectre attacks even with IBPB-on-entry active. The kernel
fix (v6.12+, backported) adds RSB fill after IBPB on affected CPUs.
Detect this gap by checking CPUID IBPB_RET bit and kernel ibpb_no_ret
bug flag, and flag systems relying on IBPB without the RSB fill fix.
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
1ff1dfbe26
fix: don't default to 0x0 ucode when unknown
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
78e4d25319
fix: bsd: use proper MSR for AMD in ucode version read fallback
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
24ed9ccaf6
enh: MDS FreeBSD: detect software mitigation as OK unless --paranoid ( #503 )
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
a49234ed96
doc: add CVE-2021-26318 (ADM Prefetch) to unsupported list
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
2ed15da028
feat: implement CVE-2023-28746 (RFDS, Register File Data Sampling)
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
0fcdc6e6cc
feat: add SLS (Straight-Line Speculation) check with --extra option
2026-04-08 22:35:52 +02:00
Stéphane Lesimple
7a7408d124
fix: add rebleet to --variant
2026-04-04 16:22:05 +00:00
Stéphane Lesimple
cccb3c0081
enh: add known fixed ucode versions for CVE-2023-23583 (Reptar) and CVE-2024-45332 (BPI)
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
090f109c52
doc: add CVE-2023-31315 (SinkClose) to the unsupported list, add categories
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
5dc9c3c18d
chore: reorder CVE list in README.md
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
a00fab131f
feat: implement CVE-2025-40300 (VMScape) and CVE-2024-45332 (BTI)
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
e0b818f8fa
chore: stalebot: disable dryrun by default
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
4af11551ba
feat: implement CVE-2024-28956 (ITS, Indirect Target Selection) vulnerability and mitigation detection
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
dfed6f35c5
doc: add note about more unsupported CVEs
...
CVE-2020-12965 - Transient Execution of Non-Canonical Accesses (SLAM)
CVE-2024-7881 - ARM Prefetcher Privilege Escalation
CVE-2024-56161 - EntrySign (AMD Microcode Signature Bypass)
CVE-2025-20623 - Shared Microarchitectural Predictor State (10th Gen Intel)
CVE-2025-24495 - Lion Cove BPU Initialization
CVE-2025-29943 - StackWarp (AMD SEV-SNP)
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
1652977f47
add a generated version of src/libs/003_intel_models.sh
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
a089ae8cef
fix: sys_interface_check() must set the caller's $msg var ( closes #533 )
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
cc6bbaad19
chore: don't include src/ generated files in build
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
2717b0a4be
doc: CVE-2020-12965 unsupported ( #478 )
2026-04-04 16:07:12 +00:00
Stéphane Lesimple
6fac2d8ff1
Merge pull request #532 from speed47/test
...
Retbleed / Downfall overhald / doc updates
2026-04-02 21:32:39 +00:00
Stéphane Lesimple
ae5493257e
doc: CVE-2018-3693 CVE-2019-1125 CVE-2019-15902 unsupported or already included
2026-04-02 23:22:31 +02:00
Stéphane Lesimple
47e202100a
doc: CVE-2018-15572 is already implemented along Spectre V2
2026-04-02 23:12:29 +02:00
Stéphane Lesimple
0edb357894
doc: CVE-2018-9056 is out of scope ( closes #169 )
2026-04-02 22:58:45 +02:00
Stéphane Lesimple
ed6a0a2882
doc: unsupported CVE list
2026-04-02 22:51:55 +02:00
Stéphane Lesimple
86e0fae48a
enh: group results by 4 in the summary line at the end of the run
2026-04-02 22:45:08 +02:00
Stéphane Lesimple
cb3b9a37fa
enh: rework VERSION adjust when we're cloned
2026-04-02 22:33:48 +02:00
Stéphane Lesimple
b9f75346d4
enh: auto-generate intel model list
2026-04-02 22:33:48 +02:00
Stéphane Lesimple
4f6dbb36c8
feat: implement Retbleed (CVE-2022-29900 CVE-2022-29901) mitigation detection
2026-04-02 22:33:48 +02:00
Stéphane Lesimple
d644941a76
chore: update dev doc with check_CVE_* header exception
2026-04-02 22:09:09 +02:00
Stéphane Lesimple
3ea8e213ec
chore: add proper header to all src/vulns/* files
2026-04-02 21:03:29 +02:00
Stéphane Lesimple
5e3033e2f5
enh: CVE-2022-40982 (Downfall) overhaul & Spectre V2 enhancements
...
Downfall:
- added `--kernel-config` support for all three Kconfig variants seen over all kernel versions up to now
- added `--kernel-map` support for `gds_select_mitigation` in `System.map`
- fixed the `--sysfs-only` mode
- added verbose information about remediation when `--explain` is used
- implemented `--paranoid mode`, requiring `GDS_MITIGATION_LOCKED` so that mitigation can't be disabled at runtime
- fixed offline mode (was wrongly looking at the system `dmesg`)
- better microcode status reporting (enabled, disabled, unsupported, unknown)
- fixed unknown (EOL) AVX-capable Intel family 6 CPUs now defaulting to affected
- fixed 2 missing known affected CPU models: INTEL_FAM6_SKYLAKE_L and INTEL_FAM6_SKYLAKE
- fixed case when we're running in a VM and the hypervisor doesn't let us read the MSR
Spectre V2:
- fix: affected_cpu: added Centaur family 7 (CentaurHauls) and Zhaoxin family 7 (Shanghai) as immune
- fix: added Centaur family 5 (CentaurHauls) and NSC family 5 (Geode by NSC) to is_cpu_specex_free()
- enh: offline mode: added detection logic by probing System.map and Kconfig
2026-04-02 21:00:30 +02:00
Stéphane Lesimple
37204869f8
chore: update dev guidelines
2026-04-02 19:55:07 +02:00
Stéphane Lesimple
d3c0f1a24d
Merge pull request #530 from speed47/test
...
chore: workflows revamp
2026-04-02 16:49:41 +00:00
Stéphane Lesimple
c799974038
chore: build: also add new files, handle github workflows
2026-04-02 18:47:00 +02:00
Stéphane Lesimple
0974871a6c
chore: build: also add new files
2026-04-02 18:43:51 +02:00
Stéphane Lesimple
952fe6a87f
Merge branch 'test' into source
2026-04-02 18:40:05 +02:00
Stéphane Lesimple
5e2af29e6a
chore: conditional workflows on all branches
2026-04-02 18:37:46 +02:00
Stéphane Lesimple
afadf53f7f
chore: add stalebot in dryrun
2026-04-02 11:15:36 +00:00
Stéphane Lesimple
5fc008f2d4
chore: add stalebot in dryrun
2026-04-02 13:13:19 +02:00
Stéphane Lesimple
e5c6d2d905
enh: CVE-2017-5715; check for unprivileged eBPF for paranoid mode
2026-04-01 20:37:54 +00:00
Stéphane Lesimple
ac327ce7c5
chore: shellcheck fixes
2026-04-01 20:10:29 +00:00
Stéphane Lesimple
03f63714b5
fix: CVE-2023-20569: logic errors with kernel_sro type change (bool => str)
2026-04-01 19:58:20 +00:00
Stéphane Lesimple
08702b07c9
fix: bad kernel/config var names
2026-04-01 19:53:34 +00:00
Stéphane Lesimple
4718134427
chore: cap_ipred unused for now, make shellcheck happy
2026-04-01 21:37:56 +02:00
Stéphane Lesimple
e23712129d
enh: rework is_cpu_affected() to enhance maintainability
2026-04-01 21:36:45 +02:00
Stéphane Lesimple
43c515ac74
enh: CVE-2017-5715 (spectre v2): make vuln assessment cap_bhi-aware
2026-04-01 21:34:12 +02:00
Stéphane Lesimple
8c3fb7b2cc
enh: CVE-2024-36357 CVE-2024-36350 (TSA): inventory of sysfs strings + consider vuln if TSA mitigation forced to user/kernel on hypervisors
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
d05601ed3f
feat: add CVE-2023-20593 (Zenbleed) mitigation detection for BSD
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
690725ccc1
enh: add BSD stubs for CVE-2022-40982 CVE-2023-20569 CVE-2023-23583, detecting unaffected CPUs
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
4875b4c71c
feat: add CVE-2020-0543 (SRBDS) mitigation detection under BSD
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
2b603c68ce
feat: add CVE-2019-11135 (TAA) mitigation detection under BSD
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
0628a3e565
enh: vmm detection has been greatly enhanced
...
We also cache the result instead of computing it every time
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
536dfb8701
enh: massive update for Spectre v2 (CVE-2017-5715)
...
The state of the mitigations for spectre v2 has been
updated several times in the kernel, this commit brings
up the script to par with the view of the most recent kernels.
When run on old kernels, that might deem the vulnerability as
mitigated, we'll reclassify it as vulnerable if applicable, unless
the `--sysfs-only` parameter is passed, which instructs the script
to blindly trust what the kernel has to say.
A full inventory of all mitigation strings found in mainline,
stable and redhat kernels since the first spectre v2 mitigation
has been added as a gigantic comment to help understanding the context.
Gory details below:
1. New structured sub-mitigation parsing ("Mitigation 3")
A new section parses the sysfs message into discrete variables for each sub-mitigation component:
- v2_base_mode: The primary mitigation (eibrs, eibrs_lfence, eibrs_retpoline, ibrs, retpoline, lfence, none) - parsed from sysfs with hardware fallback
- v2_stibp_status: STIBP state (always-on, forced, conditional, disabled, eibrs-implicit, etc.)
- v2_ibpb_mode: IBPB mode (always-on, conditional, disabled)
- v2_pbrsb_status: PBRSB-eIBRS mitigation (not-affected, sw-sequence, vulnerable)
- v2_bhi_status: BHI mitigation (not-affected, bhi_dis_s, sw-loop, retpoline, vulnerable)
- v2_vuln_module: Whether a non-retpoline kernel module is loaded
- v2_is_autoibrs: Distinguishes AMD AutoIBRS from Intel eIBRS (they have different cross-thread properties)
2. Rewritten verdict logic (Phase 4)
The old flat if/elif chain is replaced with per-base-mode branches, each checking all relevant sub-mitigations:
- LFENCE: Always VULN (reclassified in kernel v5.17)
- eIBRS path: Checks BHI, PBRSB (VMM-only), AutoIBRS STIBP, vulnerable modules, paranoid mode (IBPB always-on + SMT off)
- IBRS path: Checks IBPB, STIBP+SMT, RSB filling on Skylake+, BHI, paranoid mode
- Retpoline path: Checks compiler, runtime enable, RSB filling, BHI+RRSBA, IBPB, vulnerable modules, paranoid mode
3. Caveat accumulation pattern
A _v2_add_caveat helper collects all gaps into a single string, producing verdicts like "eIBRS active but insufficient: BHI vulnerable; STIBP not active with SMT on AMD AutoIBRS" instead of the old single-issue messages.
4. Other changes
- check_has_vmm called early in Phase 2 (for PBRSB VMM-awareness)
- explain_hypervisor variable removed - its advice is now folded into the per-path explain calls
- Offline mode gains eIBRS/AutoIBRS detection via cap_ibrs_all/cap_autoibrs
- smt_enabled variable added (via is_cpu_smt_enabled) for cross-thread checks
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
e09d0cf221
enh: check_cpu: look for cap_stibp and cap_autoibrs
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
b062fe2184
enh: CVE-2017-5715: inventory of all sysfs strings, fix --sysfs-only path
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
dfe48d67ce
enh: CVE-2018-3646: document all sysfs variations, fix --sysfs-only path
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
35d83e19a8
fix: --sysfs-only path for CVE-2018-12207 CVE-2018-3620
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
123ad1c8e6
CVE-2023-20569: detect old kernels sysfs saying mitigations are correct whereas they are not
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
b9e7f7cb8a
docs: update development guidelines
2026-04-01 21:12:23 +02:00
Stéphane Lesimple
278989d550
fix: cap_rdcl_no, cap_gds_no, cap_tsa_*_no were not setting the current CPU status as immune for their respective vulns
2026-04-01 00:47:41 +02:00
Stéphane Lesimple
b4f4d11106
fix: CVE-2018-3620: false 'VULN' status on kernels reporting CPU as unaffected and RDCL_NO can't be parsed
2026-04-01 00:41:32 +02:00
Stéphane Lesimple
4738e8f0ad
enh: draft rework of CVE-2017-5753 aka spectre v1
2026-04-01 00:22:07 +02:00
Stéphane Lesimple
b32f05b8d2
chore: readme: add a second table one about impact/mitigation, rework sections
2026-04-01 00:21:35 +02:00
Stéphane Lesimple
295324a545
chore: prepare for dev-build renaming to test-build
2026-03-31 19:49:39 +02:00
Stéphane Lesimple
efa07e7fd9
chore: set VERSION when building
2026-03-31 00:18:09 +02:00
Stéphane Lesimple
eabddf3d72
update dev docs and refactor CVE list in readme
2026-03-30 23:35:48 +02:00
Stéphane Lesimple
04221cf8c8
chore: add .gitignore
2026-03-30 23:07:59 +02:00