Commit Graph

  • cc6bbaad19 chore: don't include src/ generated files in build Stéphane Lesimple 2026-04-02 23:49:40 +02:00
  • 2717b0a4be doc: CVE-2020-12965 unsupported (#478) Stéphane Lesimple 2026-04-02 23:48:28 +02:00
  • 065f19e313 enh: add known fixed ucode versions for CVE-2023-23583 (Reptar) and CVE-2024-45332 (BPI) github-actions[bot] 2026-04-04 15:51:28 +00:00
  • 1214e63687 chore: reorder CVE list in README.md github-actions[bot] 2026-04-04 14:33:25 +00:00
  • 67be7eb116 chore: reorder CVE list in README.md github-actions[bot] 2026-04-04 14:16:02 +00:00
  • b4db134e49 feat: implement CVE-2025-40300 (VMScape) and CVE-2024-45332 (BTI) github-actions[bot] 2026-04-04 13:08:23 +00:00
  • d7cd9e8b6b add a generated version of src/libs/003_intel_models.sh github-actions[bot] 2026-04-04 12:24:10 +00:00
  • a4c3900ef0 add a generated version of src/libs/003_intel_models.sh github-actions[bot] 2026-04-04 12:21:51 +00:00
  • f2d871acff fix: spurious local keyword broke sysfs based detection (#533) (#534) Stéphane Lesimple 2026-04-02 23:31:58 +00:00
  • 1d00acbc9a chore: don't include src/ generated files in build github-actions[bot] 2026-04-02 21:56:42 +00:00
  • 90a8a3057c chore: don't include src/ generated files in build github-actions[bot] 2026-04-02 21:54:17 +00:00
  • 40b7ae9098 chore: don't include src/ generated files in build github-actions[bot] 2026-04-02 21:50:52 +00:00
  • 553a9ec60f Merge pull request #532 from speed47/test github-actions[bot] 2026-04-02 21:33:46 +00:00
  • 6fac2d8ff1 Merge pull request #532 from speed47/test Stéphane Lesimple 2026-04-02 21:32:39 +00:00
  • 27ac93dd39 doc: CVE-2018-3693 CVE-2019-1125 CVE-2019-15902 unsupported or already included github-actions[bot] 2026-04-02 21:23:44 +00:00
  • ae5493257e doc: CVE-2018-3693 CVE-2019-1125 CVE-2019-15902 unsupported or already included Stéphane Lesimple 2026-04-02 23:22:31 +02:00
  • dab7bebd3c doc: CVE-2018-15572 is already implemented along Spectre V2 github-actions[bot] 2026-04-02 21:13:46 +00:00
  • 47e202100a doc: CVE-2018-15572 is already implemented along Spectre V2 Stéphane Lesimple 2026-04-02 23:10:39 +02:00
  • 8f76537159 doc: CVE-2018-15572 is already implemented along Spectre V2 github-actions[bot] 2026-04-02 21:11:59 +00:00
  • fd7083cb08 doc: CVE-2018-9056 is out of scope (closes #169) github-actions[bot] 2026-04-02 20:59:55 +00:00
  • 0edb357894 doc: CVE-2018-9056 is out of scope (closes #169) Stéphane Lesimple 2026-04-02 22:58:45 +02:00
  • ed6a0a2882 doc: unsupported CVE list Stéphane Lesimple 2026-04-02 22:51:55 +02:00
  • 8ef4c71d36 enh: group results by 4 in the summary line at the end of the run github-actions[bot] 2026-04-02 20:46:29 +00:00
  • 86e0fae48a enh: group results by 4 in the summary line at the end of the run Stéphane Lesimple 2026-04-02 22:45:08 +02:00
  • 240d6db210 enh: rework VERSION adjust when we're cloned github-actions[bot] 2026-04-02 20:35:00 +00:00
  • cb3b9a37fa enh: rework VERSION adjust when we're cloned Stéphane Lesimple 2026-04-02 22:32:22 +02:00
  • b9f75346d4 enh: auto-generate intel model list Stéphane Lesimple 2026-04-02 22:24:43 +02:00
  • 4f6dbb36c8 feat: implement Retbleed (CVE-2022-29900 CVE-2022-29901) mitigation detection Stéphane Lesimple 2026-04-02 22:12:56 +02:00
  • d644941a76 chore: update dev doc with check_CVE_* header exception Stéphane Lesimple 2026-04-02 22:09:09 +02:00
  • fbfdb89e7a chore: add proper header to all src/vulns/* files github-actions[bot] 2026-04-02 19:35:40 +00:00
  • 3ea8e213ec chore: add proper header to all src/vulns/* files Stéphane Lesimple 2026-04-02 20:47:54 +02:00
  • 5e3033e2f5 enh: CVE-2022-40982 (Downfall) overhaul & Spectre V2 enhancements Stéphane Lesimple 2026-04-02 19:55:25 +02:00
  • 5c571bacc6 enh: CVE-2022-40982 (Downfall) overhaul github-actions[bot] 2026-04-02 18:11:41 +00:00
  • 6f8112c700 enh: CVE-2022-40982 (Downfall) overhaul github-actions[bot] 2026-04-02 18:03:22 +00:00
  • 37204869f8 chore: update dev guidelines Stéphane Lesimple 2026-04-02 19:55:07 +02:00
  • 83ebe2f75f chore: update workflows (#531) Stéphane Lesimple 2026-04-02 16:53:44 +00:00
  • 75ad60f42a Merge branch 'master' into source-build Stéphane Lesimple 2026-04-02 16:53:03 +00:00
  • 931c955765 Merge pull request #530 from speed47/test github-actions[bot] 2026-04-02 16:50:52 +00:00
  • d3c0f1a24d Merge pull request #530 from speed47/test Stéphane Lesimple 2026-04-02 16:49:41 +00:00
  • f46c743cad chore: build: also add new files, handle github workflows github-actions[bot] 2026-04-02 16:48:13 +00:00
  • c799974038 chore: build: also add new files, handle github workflows Stéphane Lesimple 2026-04-02 18:47:00 +02:00
  • 0974871a6c chore: build: also add new files Stéphane Lesimple 2026-04-02 18:43:51 +02:00
  • c5ef0c488a Merge branch 'test' into source github-actions[bot] 2026-04-02 16:41:33 +00:00
  • 952fe6a87f Merge branch 'test' into source Stéphane Lesimple 2026-04-02 18:40:05 +02:00
  • 33bdd0688d chore: conditional workflows on all branches github-actions[bot] 2026-04-02 16:39:04 +00:00
  • 7f87ade3fe chore: conditional workflows on all branches github-actions[bot] 2026-04-02 16:38:01 +00:00
  • 5e2af29e6a chore: conditional workflows on all branches Stéphane Lesimple 2026-04-02 18:36:43 +02:00
  • e2d4d14e14 chore: add stalebot in dryrun github-actions[bot] 2026-04-02 11:36:58 +00:00
  • a05f8aab34 chore: add stalebot in dryrun github-actions[bot] 2026-04-02 11:16:43 +00:00
  • 99301d1cbb chore: add stalebot in dryrun github-actions[bot] 2026-04-02 11:16:43 +00:00
  • afadf53f7f chore: add stalebot in dryrun Stéphane Lesimple 2026-04-02 13:13:19 +02:00
  • ddf2f2c723 chore: add stalebot in dryrun github-actions[bot] 2026-04-02 11:14:30 +00:00
  • 5fc008f2d4 chore: add stalebot in dryrun Stéphane Lesimple 2026-04-02 13:13:19 +02:00
  • f9c3d19f72 enh: CVE-2017-5715; check for unprivileged eBPF for paranoid mode v26.21.0401891 github-actions[bot] 2026-04-01 21:23:47 +00:00
  • 8389d9593c chore: prepare for dev-build renaming to test-build github-actions[bot] 2026-03-31 20:20:46 +00:00
  • fe376887ab enh: CVE-2017-5715; check for unprivileged eBPF for paranoid mode github-actions[bot] 2026-04-01 20:39:36 +00:00
  • e5c6d2d905 enh: CVE-2017-5715; check for unprivileged eBPF for paranoid mode Stéphane Lesimple 2026-04-01 20:37:54 +00:00
  • 7b41bcca2b chore: shellcheck fixes github-actions[bot] 2026-04-01 20:11:58 +00:00
  • ac327ce7c5 chore: shellcheck fixes Stéphane Lesimple 2026-04-01 20:10:29 +00:00
  • 03f63714b5 fix: CVE-2023-20569: logic errors with kernel_sro type change (bool => str) Stéphane Lesimple 2026-04-01 19:58:20 +00:00
  • 08702b07c9 fix: bad kernel/config var names Stéphane Lesimple 2026-04-01 19:53:34 +00:00
  • 4718134427 chore: cap_ipred unused for now, make shellcheck happy Stéphane Lesimple 2026-04-01 21:37:56 +02:00
  • e23712129d enh: rework is_cpu_affected() to enhance maintainability Stéphane Lesimple 2026-04-01 21:36:45 +02:00
  • 43c515ac74 enh: CVE-2017-5715 (spectre v2): make vuln assessment cap_bhi-aware Stéphane Lesimple 2026-04-01 21:34:12 +02:00
  • 8c3fb7b2cc enh: CVE-2024-36357 CVE-2024-36350 (TSA): inventory of sysfs strings + consider vuln if TSA mitigation forced to user/kernel on hypervisors Stéphane Lesimple 2026-04-01 21:00:48 +02:00
  • d05601ed3f feat: add CVE-2023-20593 (Zenbleed) mitigation detection for BSD Stéphane Lesimple 2026-03-31 23:11:55 +02:00
  • 690725ccc1 enh: add BSD stubs for CVE-2022-40982 CVE-2023-20569 CVE-2023-23583, detecting unaffected CPUs Stéphane Lesimple 2026-03-31 22:57:37 +02:00
  • 4875b4c71c feat: add CVE-2020-0543 (SRBDS) mitigation detection under BSD Stéphane Lesimple 2026-03-31 22:47:19 +02:00
  • 2b603c68ce feat: add CVE-2019-11135 (TAA) mitigation detection under BSD Stéphane Lesimple 2026-03-31 22:35:27 +02:00
  • 0628a3e565 enh: vmm detection has been greatly enhanced Stéphane Lesimple 2026-03-31 22:22:25 +02:00
  • 536dfb8701 enh: massive update for Spectre v2 (CVE-2017-5715) Stéphane Lesimple 2026-03-31 22:14:35 +02:00
  • e09d0cf221 enh: check_cpu: look for cap_stibp and cap_autoibrs Stéphane Lesimple 2026-03-31 22:08:02 +02:00
  • b062fe2184 enh: CVE-2017-5715: inventory of all sysfs strings, fix --sysfs-only path Stéphane Lesimple 2026-03-31 21:55:16 +02:00
  • dfe48d67ce enh: CVE-2018-3646: document all sysfs variations, fix --sysfs-only path Stéphane Lesimple 2026-03-31 21:44:51 +02:00
  • 35d83e19a8 fix: --sysfs-only path for CVE-2018-12207 CVE-2018-3620 Stéphane Lesimple 2026-03-31 21:35:18 +02:00
  • 123ad1c8e6 CVE-2023-20569: detect old kernels sysfs saying mitigations are correct whereas they are not Stéphane Lesimple 2026-03-31 21:28:16 +02:00
  • b9e7f7cb8a docs: update development guidelines Stéphane Lesimple 2026-03-31 21:17:11 +02:00
  • 151dd12e3e fix: cap_rdcl_no, cap_gds_no, cap_tsa_*_no were not setting the current CPU status as immune for their respective vulns github-actions[bot] 2026-03-31 22:48:56 +00:00
  • 278989d550 fix: cap_rdcl_no, cap_gds_no, cap_tsa_*_no were not setting the current CPU status as immune for their respective vulns Stéphane Lesimple 2026-04-01 00:47:41 +02:00
  • b4f4d11106 fix: CVE-2018-3620: false 'VULN' status on kernels reporting CPU as unaffected and RDCL_NO can't be parsed Stéphane Lesimple 2026-04-01 00:41:32 +02:00
  • 15ea90f312 enh: draft rework of CVE-2017-5753 aka spectre v1 github-actions[bot] 2026-03-31 22:23:17 +00:00
  • 4738e8f0ad enh: draft rework of CVE-2017-5753 aka spectre v1 Stéphane Lesimple 2026-04-01 00:22:07 +02:00
  • b32f05b8d2 chore: readme: add a second table one about impact/mitigation, rework sections Stéphane Lesimple 2026-03-31 22:57:00 +02:00
  • 5fd6a20ebb chore: readme: add a second table one about impact/mitigation, rework sections github-actions[bot] 2026-03-31 22:09:49 +00:00
  • e7df6a3e30 chore: readme: add a second table one about impact/mitigation github-actions[bot] 2026-03-31 22:05:17 +00:00
  • ba24551c56 chore: readme: add a second table one about impact/mitigation github-actions[bot] 2026-03-31 22:02:37 +00:00
  • 7c2699c01a chore: readme: add a second table one about impact/mitigation github-actions[bot] 2026-03-31 21:53:12 +00:00
  • 6663b6422e chore: readme: add a second table one about impact/mitigation github-actions[bot] 2026-03-31 21:43:28 +00:00
  • fe55c70658 chore: clearer CVE table in README.md github-actions[bot] 2026-03-31 21:01:37 +00:00
  • 3a822fdcf2 chore: master: remove obsolete workflow Stéphane Lesimple 2026-03-31 19:53:57 +02:00
  • d0822e1f9d chore: prepare for dev-build renaming to test-build github-actions[bot] 2026-03-31 17:53:45 +00:00
  • 295324a545 chore: prepare for dev-build renaming to test-build Stéphane Lesimple 2026-03-31 19:34:52 +02:00
  • 10e5b5749e chore: set VERSION when building github-actions[bot] 2026-03-30 22:22:20 +00:00
  • efa07e7fd9 chore: set VERSION when building Stéphane Lesimple 2026-03-30 23:46:13 +02:00
  • 4f7f83a40e chore: set VERSION when building github-actions[bot] 2026-03-30 21:51:45 +00:00
  • 4bbbd71564 update dev docs and refactor CVE list in readme github-actions[bot] 2026-03-30 21:39:55 +00:00
  • eabddf3d72 update dev docs and refactor CVE list in readme Stéphane Lesimple 2026-03-30 23:24:18 +02:00
  • c174a8b754 update dev docs and readme github-actions[bot] 2026-03-30 21:28:20 +00:00
  • 0f36203b5f chore: adjust workflow for dev-build github-actions[bot] 2026-03-30 21:08:41 +00:00
  • 04221cf8c8 chore: add .gitignore Stéphane Lesimple 2026-03-30 23:06:18 +02:00