Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Hypervisor machine with Intel CPU will have further reduced performance with mitigation of new bug

e2bs2k1e2bs2k1 Member
edited September 2025 in News

See https://comsec.ethz.ch/research/microarch/vmscape-exposing-and-exploiting-incomplete-branch-predictor-isolation-in-cloud-environments/
or
https://www.intel.com/content/www/us/en/developer/articles/news/more-information-vmscape.html

The previous mitigations seem only protect guest memories. While this new bug allow malicious guest to access secrets inside its hypervisor memory.

It's reported from some sources that while it affect both intel and amd, the performance lose on Intel could be from 10% to 51%(io heavy).

Do you enable cpu bug mitigations on linux?
  1. Do you enable cpu bug mitigations on linux?13 votes
    1. I do not care and just leave it as is.[default ON, depending on kernel config]
      38.46%
    2. Security is first for me [ON]
      38.46%
    3. I choose the mitigations I want [Partial]
        7.69%
    4. Nope. Performance is always the first [OFF]
      15.38%

Comments

  • According to the research paper: https://comsec-files.ethz.ch/papers/vmscape_sp26.pdf:

    Bad news: all recent AMD CPUs (Zen1-5) are affected as well.
    Worse news: SEV-SNP isolation broken as well for Zen1-4.
    Good news: software mitigations available for Guest kernel and Hypervisor.
    Better news: SEV-SNP on Zen5 still good against Host to Guest exploitations.

    Thanked by 1e2bs2k1
  • Getting tired of this shit.
    Security is the only way. I dont care if it get to stoneage performance era but just fucking make secure hardware and software.

    Thanked by 1Noct
Sign In or Register to comment.