x86: Lock down IO port access when securelevel is enabled
authorMatthew Garrett <mjg59@srcf.ucam.org>
Thu, 8 Mar 2012 15:35:59 +0000 (10:35 -0500)
committerBen Hutchings <ben@decadent.org.uk>
Sat, 28 Jan 2017 16:11:16 +0000 (16:11 +0000)
commit019f997a5bbdeb611bfcff4dcff307f3b335a49d
tree469cba63ece5977f55db9c61b92412b49aa69f8c
parent470bf2cd69f71af4c24f4a8f8353c2c5c2cad782
x86: Lock down IO port access when securelevel is enabled

IO port access would permit users to gain access to PCI configuration
registers, which in turn (on a lot of hardware) give access to MMIO register
space. This would potentially permit root to trigger arbitrary DMA, so lock
it down when securelevel is set.

Signed-off-by: Matthew Garrett <mjg59@srcf.ucam.org>
Gbp-Pq: Topic features/all/securelevel
Gbp-Pq: Name x86-lock-down-io-port-access-when-securelevel-is-ena.patch
arch/x86/kernel/ioport.c
drivers/char/mem.c