From: Daniel P. Berrangé Date: Thu, 6 Jun 2019 14:12:05 +0000 (+0200) Subject: docs: recommend use of md-clear feature on all Intel CPUs X-Git-Tag: v4.0.1~71 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=8da804f4f9d4d60c4efc9e71093b1c3ef8c25e67;p=thirdparty%2Fqemu.git docs: recommend use of md-clear feature on all Intel CPUs Update x86 CPU model guidance to recommend that the md-clear feature is manually enabled with all Intel CPU models, when supported by the host microcode. Signed-off-by: Daniel P. Berrangé Message-Id: <20190515141011.5315-3-berrange@redhat.com> Signed-off-by: Eduardo Habkost (cherry picked from commit 2c7e82a30774730100da9dbe68d2360459030d91) Signed-off-by: Oguz Bektas Signed-off-by: Michael Roth --- diff --git a/docs/qemu-cpu-models.texi b/docs/qemu-cpu-models.texi index 23c11dc86fb..ad040cfc981 100644 --- a/docs/qemu-cpu-models.texi +++ b/docs/qemu-cpu-models.texi @@ -200,6 +200,18 @@ Not included by default in any Intel CPU model. Should be explicitly turned on for all Intel CPU models. Note that not all CPU hardware will support this feature. + +@item @code{md-clear} + +Required to confirm the MDS (CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, +CVE-2019-11091) fixes. + +Not included by default in any Intel CPU model. + +Must be explicitly turned on for all Intel CPU models. + +Requires the host CPU microcode to support this feature before it +can be used for guest CPUs. @end table