Stéphane Lesimple
|
1571a56ce2
|
feat: add L1D flush cpuid feature bit detection
|
2018-09-19 09:05:23 +02:00 |
|
Stéphane Lesimple
|
3cf9141601
|
fix: don't display summary if no CVE was tested (e.g. --hw-only)
|
2018-09-19 09:04:52 +02:00 |
|
Stéphane Lesimple
|
bff38f1b26
|
BSD: add not-implemented-yet notice for Foreshadow-NG
|
2018-09-18 22:06:01 +02:00 |
|
Stéphane Lesimple
|
b419fe7c63
|
feat(variant4): properly detect SSBD under BSD
|
2018-09-18 22:00:32 +02:00 |
|
Stéphane Lesimple
|
e589ed7f02
|
fix: don't test SGX again in check_CVE_2018_3615, already done by is_cpu_vulnerable
|
2018-09-17 22:28:04 +02:00 |
|
Stéphane Lesimple
|
ae1206288f
|
fix: remove some harcoded /proc paths, use $procfs instead
|
2018-09-17 22:26:20 +02:00 |
|
Stéphane Lesimple
|
b44d2b5470
|
chore: remove 'experimental' notice of Foreshadow from README
|
2018-09-17 21:48:20 +02:00 |
|
Stéphane Lesimple
|
7b72c20f89
|
feat(l1tf): explode L1TF in its 3 distinct CVEs
|
2018-09-17 21:44:48 +02:00 |
|
Stéphane Lesimple
|
687ce1a7fa
|
fix: load cpuid module if absent even when /dev/cpu/0/cpuid is there
|
2018-09-08 23:15:50 +02:00 |
|
Stéphane Lesimple
|
80e0db7cc4
|
fix: don't show erroneous ucode version when latest version is unknown (fixes #238)
|
2018-08-28 20:51:46 +02:00 |
|
Stéphane Lesimple
|
b2f64e1132
|
fix README after merge
|
2018-08-18 12:09:34 +02:00 |
|
Stéphane Lesimple
|
0009c0d473
|
fix: --batch now implies --no-color to avoid colored warnings
|
2018-08-18 12:04:18 +02:00 |
|
Stéphane Lesimple
|
dd67fd94d7
|
feat: add FLUSH_CMD MSR availability detection (part of L1TF mitigation)
|
2018-08-16 19:05:09 +02:00 |
|
Stéphane Lesimple
|
339ad31757
|
fix: add missing l1tf CPU vulnerability display in hw section
|
2018-08-16 15:19:29 +02:00 |
|
Stéphane Lesimple
|
794c5be1d2
|
feat: add optional git describe support to display inter-release version numbers
|
2018-08-16 15:18:47 +02:00 |
|
Stéphane Lesimple
|
a7afc585a9
|
fix several incorrect ucode version numbers
|
2018-08-16 10:51:55 +02:00 |
|
Stéphane Lesimple
|
fc1dffd09a
|
feat: implement detection of latest known versions of intel microcodes
|
2018-08-15 12:53:49 +02:00 |
|
Stéphane Lesimple
|
e942616189
|
feat: initial support for L1TF
|
2018-08-15 12:05:08 +02:00 |
|
Stéphane Lesimple
|
360be7b35f
|
fix: hide arch_capabilities_msr_not_read warning under !intel
|
2018-08-13 15:42:56 +02:00 |
|
Stéphane Lesimple
|
5f59257826
|
bump to v0.39
|
2018-08-13 15:33:03 +02:00 |
|
Stéphane Lesimple
|
92d59cbdc1
|
chore: adjust some comments, add 2 missing inits
|
2018-08-11 10:31:10 +02:00 |
|
Stéphane Lesimple
|
4747b932e7
|
feat: add detection of RSBA feature bit and adjust logic accordingly
|
2018-08-10 10:26:23 +02:00 |
|
Stéphane Lesimple
|
860023a806
|
fix: ARCH MSR was not read correctly, preventing proper SSB_NO and RDCL_NO detection
|
2018-08-10 10:26:23 +02:00 |
|
Stéphane Lesimple
|
ab67a9221d
|
feat: read/write msr now supports msr-tools or perl as dd fallback
|
2018-08-10 10:26:23 +02:00 |
|
Stéphane Lesimple
|
be15e47671
|
chore: setting master to v0.38+
|
2018-08-09 14:25:22 +02:00 |
|
Stéphane Lesimple
|
21af561148
|
bump to v0.38
|
2018-08-07 10:55:50 +02:00 |
|
Stéphane Lesimple
|
cb740397f3
|
feat(arm32): add spectrev1 mitigation detection
|
2018-08-07 10:42:03 +02:00 |
|
Stéphane Lesimple
|
84195689af
|
change: default to --no-explain, use --explain to get detailed mitigation help
|
2018-08-04 16:31:41 +02:00 |
|
Stéphane Lesimple
|
b637681fa8
|
fix: debug output: msg inaccuracy for ARM checks
|
2018-08-04 16:19:54 +02:00 |
|
Stéphane Lesimple
|
9316c30577
|
fix: armv8: models < 0xd07 are not vulnerable
|
2018-08-04 16:19:54 +02:00 |
|
Stéphane Lesimple
|
0f0d103a89
|
fix: correctly init capabilities_ssb_no var in all cases
|
2018-07-26 10:18:14 +02:00 |
|
Stéphane Lesimple
|
b262c40541
|
fix: remove spurious character after an else statement
|
2018-07-25 21:55:50 +02:00 |
|
Stéphane Lesimple
|
cc2910fbbc
|
fix: read_cpuid: don't use iflag=skip_bytes for compat with old dd versions
This closes #215 #199 #193
|
2018-07-23 09:12:30 +02:00 |
|
Stéphane Lesimple
|
cf06636a3f
|
fix: prometheus output: use printf for proper \n interpretation (#204)
|
2018-06-21 23:35:51 +02:00 |
|
Stéphane Lesimple
|
60077c8d12
|
fix(arm): rewrite vuln logic from latest arm statement for Cortex A8 to A76
|
2018-06-21 23:24:18 +02:00 |
|
Stéphane Lesimple
|
e54e8b3e84
|
chore: remove warning in README, fix display indentation
|
2018-05-24 16:32:53 +02:00 |
|
Stéphane Lesimple
|
39c778e3ac
|
fix(amd): AMD families 0x15-0x17 non-arch MSRs are a valid way to control SSB
|
2018-05-23 23:08:07 +02:00 |
|
Stéphane Lesimple
|
2cde6e4649
|
feat(ssbd): add detection of proper CPUID bits on AMD
|
2018-05-23 22:50:52 +02:00 |
|
Stéphane Lesimple
|
f4d51e7e53
|
fix(variant4): add another detection way for Red Hat kernel
|
2018-05-23 22:47:54 +02:00 |
|
Stéphane Lesimple
|
85d46b2799
|
feat(variant4): add more detailed explanations
|
2018-05-23 21:08:58 +02:00 |
|
Stéphane Lesimple
|
61e02abd0c
|
feat(variant3a): detect up to date microcode
|
2018-05-23 21:08:08 +02:00 |
|
Stéphane Lesimple
|
114756fab7
|
fix(amd): not vulnerable to variant3a
|
2018-05-23 20:38:43 +02:00 |
|
Stéphane Lesimple
|
ca391cbfc9
|
fix(variant2): correctly detect IBRS/IBPB in SLES kernels
|
2018-05-22 12:06:46 +02:00 |
|
Stéphane Lesimple
|
68af5c5f92
|
feat(variant4): detect SSBD-aware kernel
|
2018-05-22 12:05:46 +02:00 |
|
Stéphane Lesimple
|
19be8f79eb
|
doc: update README with some info about variant3 and variant4
|
2018-05-22 09:43:29 +02:00 |
|
Stéphane Lesimple
|
f75cc0bb6f
|
feat(variant4): add sysfs mitigation hint and some explanation about the vuln
|
2018-05-22 09:39:11 +02:00 |
|
Stéphane Lesimple
|
f33d65ff71
|
feat(variant3a): add information about microcode-sufficient mitigation
|
2018-05-22 09:38:29 +02:00 |
|
Stéphane Lesimple
|
725eaa8bf5
|
feat(arm): adjust vulnerable ARM CPUs for variant3a and variant4
|
2018-05-22 09:19:29 +02:00 |
|
Stéphane Lesimple
|
c6ee0358d1
|
feat(variant4): report SSB_NO CPUs as not vulnerable
|
2018-05-22 09:18:30 +02:00 |
|
Stéphane Lesimple
|
22d0b203da
|
fix(ssb_no): rename ssbd_no to ssb_no and fix shift
|
2018-05-22 00:38:31 +02:00 |
|
Stéphane Lesimple
|
3062a8416a
|
fix(msg): add missing words
|
2018-05-22 00:10:08 +02:00 |
|
Stéphane Lesimple
|
6a4318addf
|
feat(variant3a/4): initial support for 2 new CVEs
|
2018-05-22 00:06:56 +02:00 |
|
Stéphane Lesimple
|
c19986188f
|
fix(variant2): adjust detection for SLES kernels
|
2018-05-19 09:53:12 +02:00 |
|
Stéphane Lesimple
|
fb52dbe7bf
|
set master branch to v0.37+
|
2018-04-20 20:34:42 +02:00 |
|
Stéphane Lesimple
|
edebe4dcd4
|
bump to v0.37
|
2018-04-18 23:51:45 +02:00 |
|
Stéphane Lesimple
|
83ea78f523
|
fix: arm: also detect variant 1 mitigation when using native objdump
|
2018-04-17 18:50:32 +02:00 |
|
Stéphane Lesimple
|
602b68d493
|
fix(spectrev2): explain that retpoline is possible for Skylake+ if there is RSB filling, even if IBRS is still better
|
2018-04-16 09:27:28 +02:00 |
|
Stéphane Lesimple
|
97bccaa0d7
|
feat: rephrase IBPB warning when only retpoline is enabled in non-paranoid mode
|
2018-04-16 09:13:25 +02:00 |
|
Stéphane Lesimple
|
68e619b0d3
|
feat: show RSB filling capability for non-Skylake in verbose mode
|
2018-04-16 09:08:25 +02:00 |
|
Stéphane Lesimple
|
a6f4475cee
|
feat: make IBRS_FW blue instead of green
|
2018-04-16 09:07:54 +02:00 |
|
Stéphane Lesimple
|
223f5028df
|
feat: add --paranoid to choose whether we require IBPB
|
2018-04-15 23:05:30 +02:00 |
|
Stéphane Lesimple
|
c0108b9690
|
fix(spectre2): don't explain how to fix when NOT VULNERABLE
|
2018-04-15 20:55:55 +02:00 |
|
Stéphane Lesimple
|
a3016134bd
|
feat: make RSB filling support mandatory for Skylake+ CPUs
|
2018-04-15 20:55:31 +02:00 |
|
Stéphane Lesimple
|
59d85b39c9
|
feat: detect RSB filling capability in the kernel
|
2018-04-15 20:55:01 +02:00 |
|
Stéphane Lesimple
|
baaefb0c31
|
fix: remove shellcheck warnings
|
2018-04-11 22:24:03 +02:00 |
|
Stéphane Lesimple
|
10b8d94724
|
feat: detect latest Red Hat kernels' RO ibpb_enabled knob
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
8606e60ef7
|
refactor: no longer display the retoline-aware compiler test when we can't tell for sure
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
6a48251647
|
fix: regression in 51aeae25, when retpoline & ibpb are enabled
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
f4bf5e95ec
|
fix: typos
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
60eac1ad43
|
feat: also do PTI performance check with (inv)pcid for BSD
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
b3cc06a6ad
|
fix regression introduced by 82c25dc
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
5553576e31
|
feat(amd/zen): re-introduce IBRS for AMD except ZEN family
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
e16ad802da
|
feat(ibpb=2): add detection of SMT before concluding the system is not vulnerable
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
29c294edff
|
feat(bsd): explain how to mitigate variant2
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
59714011db
|
refactor: IBRS_ALL & RDCL_NO are Intel-only
|
2018-04-10 22:51:45 +02:00 |
|
Stéphane Lesimple
|
51e8261a32
|
refactor: separate hw checks for Intel & AMD
|
2018-04-10 22:49:28 +02:00 |
|
Stéphane Lesimple
|
2a4bfad835
|
refactor: add is_amd and is_intel funcs
|
2018-04-10 22:49:28 +02:00 |
|
Stéphane Lesimple
|
7e52cea66e
|
feat(spectre2): refined how status of this vuln is decided and more precise explanations on how to fix
|
2018-04-10 22:49:28 +02:00 |
|
Stéphane Lesimple
|
0eabd266ad
|
refactor: decrease default verbosity for some tests
|
2018-04-05 22:20:16 +02:00 |
|
Stéphane Lesimple
|
b77fb0f226
|
fix: don't override ibrs/ibpb results with later tests
|
2018-04-05 22:04:20 +02:00 |
|
Stéphane Lesimple
|
89c2e0fb21
|
fix(amd): show cpuinfo and ucode details
|
2018-04-05 21:39:27 +02:00 |
|
Stéphane Lesimple
|
b88f32ed95
|
feat: print raw cpuid, and fetch ucode version under BSD
|
2018-04-05 00:07:12 +02:00 |
|
Stéphane Lesimple
|
7a4ebe8009
|
refactor: rewrite read_cpuid to get more common code parts between BSD and Linux
|
2018-04-05 00:06:24 +02:00 |
|
Stéphane Lesimple
|
0919f5c236
|
feat: add explanations of what to do when a vulnerability is not mitigated
|
2018-04-05 00:03:04 +02:00 |
|
Stéphane Lesimple
|
de02dad909
|
feat: rework Spectre V2 mitigations detection w/ latest vanilla & Red Hat 7 kernels
|
2018-04-05 00:01:54 +02:00 |
|
Stéphane Lesimple
|
07484d0ea7
|
add dump of variables at end of script in debug mode
|
2018-04-04 23:58:15 +02:00 |
|
Stéphane Lesimple
|
a8b557b9e2
|
fix(cpu): skip CPU checks if asked to (--no-hw) or if inspecting a kernel of another architecture
|
2018-04-03 19:36:28 +02:00 |
|
Stéphane Lesimple
|
619b2749d8
|
fix(sysfs): only check for sysfs for spectre2 when in live mode
|
2018-04-03 19:32:36 +02:00 |
|
Stéphane Lesimple
|
94857c983d
|
update readme
|
2018-04-03 16:00:36 +02:00 |
|
Stéphane Lesimple
|
056ed00baa
|
feat(arm): detect spectre variant 1 mitigation
|
2018-04-03 15:52:25 +02:00 |
|
Stéphane Lesimple
|
aef99d20f3
|
fix(pti): when PTI activation is unknown, don't say we're vulnerable
|
2018-04-03 12:45:17 +02:00 |
|
Stéphane Lesimple
|
e2d7ed2243
|
feat(arm): support for variant2 and meltdown mitigation detection
|
2018-04-01 17:50:18 +02:00 |
|
Stéphane Lesimple
|
eeaeff8ec3
|
set version to v0.36+ for master branch between releases
|
2018-04-01 17:45:01 +02:00 |
|
Stéphane Lesimple
|
f5269a362a
|
feat(bsd): add retpoline detection for BSD
|
2018-04-01 17:42:29 +02:00 |
|
Stéphane Lesimple
|
f3883a37a0
|
fix(xen): adjust message for DomUs w/ sysfs
|
2018-03-31 13:44:04 +02:00 |
|
Stéphane Lesimple
|
b6fd69a022
|
release: v0.36
|
2018-03-27 23:08:38 +02:00 |
|
Stéphane Lesimple
|
7adb7661f3
|
enh: change colors and use red only to report vulnerability
|
2018-03-25 18:15:08 +02:00 |
|
Stéphane Lesimple
|
c7892e3399
|
update README.md
|
2018-03-25 14:18:39 +02:00 |
|
Stéphane Lesimple
|
aa74315df4
|
feat: speed up kernel version detection
|
2018-03-25 13:42:19 +02:00 |
|
Stéphane Lesimple
|
0b8a09ec70
|
fix: mis adjustments for BSD compat
|
2018-03-25 13:26:00 +02:00 |
|