shell-things/etc/default/grub.d/mitigations.cfg

7 lines
404 B
INI

# Enable all mitigation for Microarchitectural Data Sampling attack
# including disabling Simultaneous multithreading
# https://en.wikipedia.org/wiki/Simultaneous_multithreading
# WARNING: This may have performance impact!
# https://www.kernel.org/doc/html/latest/admin-guide/hw-vuln/mds.html
GRUB_CMDLINE_LINUX_DEFAULT="$GRUB_CMDLINE_LINUX_DEFAULT l1tf=full,force mds=full,nosmt mitigations=auto,nosmt"