Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Kernel & Hardware
  • Search

Enabling VMScape mitigation [SOLVED]

Kernel not recognizing your hardware? Problems with power management or PCMCIA? What hardware is compatible with Gentoo? See here. (Only for kernels supported by Gentoo.)
Post Reply
Advanced search
4 posts • Page 1 of 1
Author
Message
ExecutorElassus
Veteran
Veteran
User avatar
Posts: 1525
Joined: Thu Mar 11, 2004 11:12 pm
Location: Berlin, Germany

Enabling VMScape mitigation [SOLVED]

  • Quote

Post by ExecutorElassus » Fri Oct 24, 2025 2:37 pm

I have a Ryzen 7 CPU, which apparently has a vulnerability to the VMScape exploit (see here). In the kernel options, it should be an available switch under "CPU Vulnerabilities", but I don't see it. `lscpu` reports that the CPU is vulnerable to the exploit. The Kernel setting depends on CPU_MITIGATIONS=y and KVM=n, which is the case.

Is there some setting I need to make to make this mitigation available? Is there some other setting I need? Current kernel is gentoo-linux-6.17.2.

Cheers,

EE
Last edited by ExecutorElassus on Fri Oct 24, 2025 3:45 pm, edited 1 time in total.
Top
grknight
Retired Dev
Retired Dev
Posts: 2565
Joined: Fri Feb 20, 2015 9:36 pm

  • Quote

Post by grknight » Fri Oct 24, 2025 2:46 pm

Since KVM=n, you cannot be attacked as this is about a guest hypervisor attacking a host.

If you want the mitigation, set KVM=y and then MITIGATION_VMSCAPE=y
Top
ExecutorElassus
Veteran
Veteran
User avatar
Posts: 1525
Joined: Thu Mar 11, 2004 11:12 pm
Location: Berlin, Germany

  • Quote

Post by ExecutorElassus » Fri Oct 24, 2025 3:45 pm

Oh, my mistake then. I thought the dependency was on KVM being set to =n (which is how it's set on my system). I guess lscpu doesn't take into account whether the kernel configuration makes it possible to exploit the vulnerability in the first place.

Thanks for clarifying!

EE
Top
Hu
Administrator
Administrator
Posts: 24400
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Fri Oct 24, 2025 5:44 pm

This is a common misreading of the presented data. The dependency was probably shown as KVM [=n]. This tells you that it requires KVM enabled, and that you presently have it set to =n. If it was telling you that the symbol required you to disable KVM, I think that it would be written as !KVM [=n]. This is from memory, so I might not have the text exactly right.
Top
Post Reply

4 posts • Page 1 of 1

Return to “Kernel & Hardware”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic