On Wed, Dec 11, 2019 at 12:49 PM Marios Pomonis <pomonis@xxxxxxxxxx> wrote: > > This fixes Spectre-v1/L1TF vulnerabilities in > vmx_read_guest_seg_selector(), vmx_read_guest_seg_base(), > vmx_read_guest_seg_limit() and vmx_read_guest_seg_ar(). > These functions contain index computations based on the > (attacker-influenced) segment value. > > Fixes: commit 2fb92db1ec08 ("KVM: VMX: Cache vmcs segment fields") > > Signed-off-by: Nick Finco <nifi@xxxxxxxxxx> > Signed-off-by: Marios Pomonis <pomonis@xxxxxxxxxx> > Reviewed-by: Andrew Honig <ahonig@xxxxxxxxxx> > Cc: stable@xxxxxxxxxxxxxxx Reviewed-by: Jim Mattson <jmattson@xxxxxxxxxx>