x86: Lock down IO port access when securelevel is enabled
authorMatthew Garrett <mjg59@srcf.ucam.org>
Thu, 8 Mar 2012 15:35:59 +0000 (10:35 -0500)
committerYves-Alexis Perez <corsac@debian.org>
Wed, 21 Feb 2018 15:29:03 +0000 (15:29 +0000)
commit003f0a3a9c5d488e9b734bdf27dfdd20ed95ddb4
tree30cf914dd0d9260be41d866ad9a4d36a4a12cddf
parent72c010c9f8bd34922f7084b97142a8b3d03ce028
x86: Lock down IO port access when securelevel is enabled

IO port access would permit users to gain access to PCI configuration
registers, which in turn (on a lot of hardware) give access to MMIO register
space. This would potentially permit root to trigger arbitrary DMA, so lock
it down when securelevel is set.

Signed-off-by: Matthew Garrett <mjg59@srcf.ucam.org>
Gbp-Pq: Topic features/all/securelevel
Gbp-Pq: Name x86-lock-down-io-port-access-when-securelevel-is-ena.patch
arch/x86/kernel/ioport.c
drivers/char/mem.c