Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No. The "master" software fix to Meltdown keeps userland and the kernel from trivially sharing kernel memory pages. If your guest kernel doesn't have this fix applied, then your guest userland shares pages with your guest kernel, and guest processes can dump kernel memory.


In theory it should be possible for a hyper visor to retrofit a fix into a guest, but it's messy and I doubt anyone will ever do it. Could be fun though.

Quick sketch: disable EPT and go back to shadow paging. Maintain a third page table with any kernel pages unmapped. Invisibly swap between on syscalls.


This sounds really slow to me. What is the overhead of "disable EPT and go back to shadow paging", or what was the performance win of EPT?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: