Mitigations to the “Memory Sinkhole”
blog.jacobtorrey.com
blog.jacobtorrey.com
I thought one of the features of hardware virtualization support was to mask the fact that you are being virtualized, in which case nesting would be a requirement?
and the exploit affects CPUs below sandy bridge, so that's of no use to the affected users if they want to use a virtualization solution inside their main OS (instead of cooperating with the underlying hypervisor)
> I thought one of the features of hardware virtualization support was to mask the fact that you are being virtualized
You could simply have a virtual CPU that does not support virtualization.
Or you could trap the offending instructions and emulate it in software. But that would come at a performance penalty that GP wants to avoid.
The problem is that this is extremely slow. Haswell's shadow VMCS makes it less slow, but I doubt it performs particularly well. Another downside is that the CPU only supports two levels of page tables, so it gets awkward to make everything work securely and correctly without emulating a level of page tables as well.
(If KVM allowed moving the APIC, then you could use this to escalate privileges from guest kernel mode to /guest/ SMM, and KVM is adding guest SMM soon, but that's a much less interesting attack IMO.)