4 ms·
Isn't it possible to restrict what memory regions a device may have access to?
by screcth 2y ago
Isn't it possible to restrict what memory regions a device may have access to?
- adastra22 2y agoNo, it's on the PCIe bus. It sends data straight to RAM, circumventing the memory controller on the CPU. SOME systems have write protection logic on the RAM controllers themselves, but this is not universal.
- Firerouge 2y ago> SOME systems have write protection logic on the RAM controllers themselves How can one tell if a system has RAM controller based security, what name does this write protection go by?
- stefan_ 2y agoMaybe the grandparent is trying to refer to IOMMUs.
- adastra22 2y agoThis. Your system will almost certainly have an IOMMU. But that can’t be said for all systems that the Linux kernel supports.
- lathiat 2y agoHowever your IOMMU may not actually be in use. It's not in use by default on Linux and on most Linux distros as it tends to break things on random hardware that isn't setup right. It tends to work most of the time on servers. Ubuntu 22.04 tried to turn it on by default but switched it off again due to random mostly graphics related regressions on random hardware: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1971699 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1971699 Some other history: https://www.phoronix.com/news/Intel-IOMMU-Gfx-Default-Try https://www.phoronix.com/news/Intel-IOMMU-Gfx-Default-Try We really do need it though. I am always reminded of the very old Apple "Firewire Memory Bypass" which rendered flames to the screen just by plugging a firewire device in - because firewire had direct and originally unprotected DMA access: https://www.pentestpartners.com/security-blog/hack-demo-video/firewire-memory-attack-a-how-to-video/ https://www.pentestpartners.com/security-blog/hack-demo-vide... It is for this reason that even without IOMMU, as a workaround, you have to often give permission to thunderbolt devices to connect. Some details on that here: https://wiki.archlinux.org/title/Thunderbolt https://wiki.archlinux.org/title/Thunderbolt There is also a small but noticable performance hit to using the IOMMU, not so noticable on a general setup but if you are doing high-speed disk & network I/O like ceph storage in excess of 10Gbit/s or millions of IOPS you will notice it. You can Google that. You can also run into other weird behaviour, for example when using kdump to create a kernel crash dump it will kexec from the old kernel into a new kernel to produce the crash dump. The system doesn't go through a firmwire/uefi/bios reset so the hardware state of network cards, etc, doesn't get reset. So if you have any hardware driver state that isn't properly reset, you might for example have your network card DMA a packet directly into host memory in the time window before it gets reset. With IOMMU that might trigger errors, with it off it will hopefully not overwrite anything important but may also overwrite something important :) These things are all of course fixable, but since it's still off by default much of the time, lots of these bugs persist for a long time. Disclaimer: I am not an expert in this area it's just anecodtes from my life as a Linux Geek & Support Engineer. Should be about 90% accurate but I am sure I glossed over some solid details :)
- surajrmal 2y agoIommus are very common on PC grade hardware, as well as premium smart phones. They just aren't that common on lower end phones and iot devices, but pcie is also fairly uncommon on those devices which makes your comment a bit confusing.
- AlotOfReading 2y agoThere's a lot of moderately powerful embedded Linux systems out there that either don't have an MMU equivalent or have one that the vendor BSP doesn't use by default. Too give one example, Xilinx doesn't set up the SMMU for AXI DMA devices on Zynq by default, iirc.
- codedokode 2y agoAs I understand, Zync is a FPGA, it is not used in consumer devices like laptops and smartphones so nothing bad happens even if there is a vulnerability.
- AlotOfReading 2y agoMost of the Zynq line include hard ARM A and/or R processors. Either way, just because something isn't in consumer electronics doesn't man vulnerabilities aren't important. Imagine a vulnerability in the control systems for your car or the planes you use.