Bug 2001059
| Summary: | gcc: add patch to mitigate ARM CVE-2021-35465 | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | devthomp |
| Component: | gcc | Assignee: | Marek Polacek <mpolacek> |
| gcc sub component: | system-version | QA Contact: | qe-baseos-tools-bugs |
| Status: | CLOSED NOTABUG | Docs Contact: | |
| Severity: | low | ||
| Priority: | unspecified | CC: | ahajkova, fweimer, jakub, ohudlick |
| Version: | 9.0 | Keywords: | Bugfix, Triaged |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | No Doc Update | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-09-14 21:10:41 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
devthomp
2021-09-03 16:42:18 UTC
(In reply to devthomp from comment #0) > Description of problem: > Certain Arm products before 2021-08-23 do not properly consider the effect > of exceptions on a VLLDM instruction. A Non-secure handler may have read or > write access to part of a Secure context. A compiler patch was put together > to mitigate this issue. > > Because there are no current products affected by this issue as it is tied > to ARM M-profile processors this hardening bug is being raised. This is to > add the mitigation to gcc as was done in the gnu branch. Cortex-M is not a supported target. The upstream patches update the arm (not aarch64) backend which we do not use. Would you please clarify why we would need to backport this patch? Thanks. Perhaps I misunderstood patch intent. I was under the impression it would also mitigate cross compiling to that platform. Which our clients may be doing. But we don't support that, do we? The product it RHEL 9 so the sub component can't be the GCC Toolset because we don't have it yet. That said, since Richard said he would backport the patches to 11, we'll get them for free when updating from Fedora gcc 11. I don't plan to update GTS 10 gcc though. QE work would be sanity-only. (In reply to devthomp from comment #2) > Perhaps I misunderstood patch intent. I was under the impression it would > also mitigate cross compiling to that platform. > Which our clients may be doing. Cross-compilation is not supported. It would require rebuilding the toolchain from sources, which isn't supported either. (In reply to Florian Weimer from comment #4) > (In reply to devthomp from comment #2) > > Perhaps I misunderstood patch intent. I was under the impression it would > > also mitigate cross compiling to that platform. > > Which our clients may be doing. > > Cross-compilation is not supported. It would require rebuilding the > toolchain from sources, which isn't supported either. Resolving as not a bug given this. |