ccc-linux-guest-hardening icon indicating copy to clipboard operation
ccc-linux-guest-hardening copied to clipboard

[Hardening aspect] Overall PCI subsystem hardening

Open ereshetova opened this issue 11 months ago • 0 comments

Problem

The core PCI subsystem in a CoCo guest performs a lot of activity (mainly consuming data from host-controlled pci config space) where it can receive malicious input from untrusted host. In order to minimize the risk, we initially developed patches in that disable a lot of PCI functionality that is not needed in CoCo guest (early pci, pci quirks, etc). However, this is not a proper approach and instead we need to find a way to hardened the needed areas. This potentially means creating solution to establish a trust in pci config space configuration that host provides.

ereshetova avatar Mar 13 '24 07:03 ereshetova