Pulling the plug sounds easier :)
Pulling the plug sounds easier :)
* The PCI bus access is given to the _USB hub_, since that's what's connected to PCI, not to the USB device you plugged in. The USB hub can talk to the USB device using whatever restrictive protocol it wants to. The USB protocol doesn't give DMA access to devices -- it polls registers on the devices for commands and data.
* Even if it were a hostile device connected to the PCI bus, modern machines, both desktop-class (e.g. x64) and mobile (e.g. modern ARM cores in cellphones) use IOMMUs to give a virtual view of just the device's own addressable memory to the device, not the full system memory map.
(I might be mistaken about some of this, but that's my understanding.)
Perhaps if the goal was to sabotage a presentation or some 007 style attack...
In any event, I didn't mean to say that the vulnerability is not worth fixing. It definitely is. It just seems like a relatively benign issue compared to the daily barrage of hair raising security flaws.
High security servers that don't have typical interfaces are super common in government facilities. Sometimes they'll shove glue into the USB and sometimes the USB is the only method of accessing the system.